Story perspectives
Shai Hulud Worm Compromises 19,000 Code Repositories
11/24/2025
1 of 1
Story summary
- A new wave of the Shai Hulud npm worm compromised over 19,000 public code repositories.
- The attack escalates from a September 2025 incident that affected about 180 libraries.
- The worm runs malicious code during npm package installation to steal developers' credentials.
- Attackers have begun directly dumping stolen credentials into public GitHub repositories.
- Security experts urge developers to uninstall compromised packages, rotate credentials, and audit repositories.
