Skip to content

Shai-Hulud

Shai-Hulud is a self-propagating software supply-chain threat cluster centered on malicious npm package compromises that began in September 2025 and later evolved into broader multi-wave and multi-ecosystem activity.

Profile source: Mallory opens in a new tab

Shai-Hulud

Family profile

Shai-Hulud is a self-propagating software supply-chain threat cluster centered on malicious npm package compromises that began in September 2025 and later evolved into broader multi-wave and multi-ecosystem activity. It is widely characterized as the first truly self-propagating npm worm. The campaign initially spread by compromising popular JavaScript packages, harvesting secrets from developer and CI/CD environments, and then using stolen publishing credentials and repository access to inject malicious code into additional packages controlled by affected maintainers. More than 500 npm packages were reported compromised in early waves, with later reporting describing recurring variants and related offshoots such as Shai-Hulud 2.0 and Mini Shai-Hulud. Some reporting also places the activity cluster in an evolutionary line leading toward the modular Miasma framework, although separate incidents that merely resemble Shai-Hulud have also been explicitly assessed as unattributed or false-flagged.

Core tradecraft associated with Shai-Hulud includes credential theft, secret reconnaissance, exfiltration, persistence, and automated propagation through trusted developer infrastructure. Documented behavior includes harvesting GitHub personal access tokens, npm tokens, cloud credentials, CI/CD secrets, and other sensitive material from local environments, repositories, workflow logs, and metadata services. The malware has used tools and logic comparable to TruffleHog-style secret scanning, abuse of GitHub Actions and self-hosted runners, malicious workflow injection, repository modification, and republishing of trojanized packages using compromised maintainer rights or trusted publishing flows. Exfiltration has repeatedly leveraged GitHub itself, including attacker-created repositories, commits, and workflow channels, allowing the actor to blend command-and-control and data theft into legitimate developer traffic.

Later variants expanded the engineering sophistication of the campaign. Reported enhancements across subsequent waves include Bun-based staging and execution, modular dispatch and payload architecture, dead-drop command retrieval through public GitHub artifacts, persistence through developer-environment hooks and operating-system autostart mechanisms, and abuse of trusted automation identities for commit forgery or persona spoofing. Some variants also targeted AI-assisted developer tooling and editor configuration files to gain execution when repositories were opened or developer sessions started. A November 2025 wave reportedly added a destructive fallback that attempted to erase user data when useful credentials could not be found, indicating that some branches of the activity moved beyond pure credential theft into destructive behavior.

Shai-Hulud primarily targets software maintainers, developer workstations, CI/CD runners, and organizations that depend on high-trust open-source packages. Victim environments have included npm package maintainers, GitHub repositories, and cloud-connected build systems. The campaign’s operational objective is best understood as theft of credentials and privileged access that can be reused for further compromise and propagation across software ecosystems. While multiple later incidents have been described as Shai-Hulud-like because they share propagation patterns, GitHub-centric exfiltration, or Bun-based loaders, only directly attributed activity should be considered part of the Shai-Hulud cluster.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 1, 2026
Last activity
Sep 1, 2026
Feed role
C2
Host form
0 IP / 2 hostnames

Leading locations

  • US2

Leading providers

  • Google LLC2

Infrastructure traits

  • Anycast 2
  • Hosting 2

MITRE ATT&CK

Shai-Hulud in ATT&CK

88 distinct techniques

Techniques

88 techniques
T1195 Supply Chain Compromise T1528 Steal Application Access Token T1574 Hijack Execution Flow T1552.005 Cloud Instance Metadata API T1562 Impair Defenses T1027 Obfuscated Files or Information T1567 Exfiltration Over Web Service T1568 Dynamic Resolution T1552.003 Shell History T1070.004 File Deletion T1555 Credentials from Password Stores T1518 Software Discovery T1497.001 System Checks T1546 Event Triggered Execution T1059.007 JavaScript T1119 Automated Collection T1552.001 Credentials In Files T1105 Ingress Tool Transfer T1195.002 Compromise Software Supply Chain T1078.004 Cloud Accounts T1496 Resource Hijacking T1543.001 Launch Agent T1567.001 Exfiltration to Code Repository T1059.004 Unix Shell T1543.002 Systemd Service T1071.004 DNS T1574.007 Path Interception by PATH Environment Variable T1053 Scheduled Task/Job T1008 Fallback Channels T1526 Cloud Service Discovery T1649 Steal or Forge Authentication Certificates T1570 Lateral Tool Transfer T1195.001 Compromise Software Dependencies and Development Tools T1083 File and Directory Discovery T1552 Unsecured Credentials T1003 OS Credential Dumping T1059 Command and Scripting Interpreter T1204.002 Malicious File T1104 Multi-Stage Channels T1140 Deobfuscate/Decode Files or Information T1556 Modify Authentication Process T1041 Exfiltration Over C2 Channel T1055 Process Injection T1555.003 Credentials from Web Browsers T1078 Valid Accounts T1106 Native API T1136 Create Account T1082 System Information Discovery T1053.006 Systemd Timers T1127 Trusted Developer Utilities Proxy Execution T1057 Process Discovery T1098.001 Additional Cloud Credentials T1497 Virtualization/Sandbox Evasion T1059.006 Python T1037 Boot or Logon Initialization Scripts T1036 Masquerading T1563.001 SSH Hijacking T1199 Trusted Relationship T1550.001 Application Access Token T1567.002 Exfiltration to Cloud Storage T1556.006 Multi-Factor Authentication T1213 Data from Information Repositories T1543 Create or Modify System Process T1566 Phishing T1574.001 DLL T1485 Data Destruction T1071 Application Layer Protocol T1071.001 Web Protocols T1548.005 Temporary Elevated Cloud Access T1027.013 Encrypted/Encoded File T1055.001 Dynamic-link Library Injection T1568.003 DNS Calculation T1614.001 System Language Discovery T1574.013 KernelCallbackTable T1091 Replication Through Removable Media T1613 Container and Resource Discovery T1547 Boot or Logon Autostart Execution T1059.001 PowerShell T1593 Search Open Websites/Domains T1564.001 Hidden Files and Directories T1505 Server Software Component T1136.003 Cloud Account T1548 Abuse Elevation Control Mechanism T1133 External Remote Services T1068 Exploitation for Privilege Escalation T1539 Steal Web Session Cookie T1195.003 Compromise Hardware Supply Chain T1578.003 Delete Cloud Instance

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.