Story perspectives
Shai-Hulud Worm Strikes 700 Packages, Threatens Developer Security
11/27/2025
1 of 1
Story summary
- The Shai-Hulud worm variant infected about 640 NPM packages, expanding its reach beyond the September attack.
- The latest wave compromised around 700 packages and created over 27,000 malicious GitHub repositories.
- The malware targets developer credentials, including API tokens and SSH keys, and uses malicious preinstall scripts to propagate.
- Experts warn that the data-wiping capability makes this year's most impactful supply chain attack, urging developers to rotate credentials and monitor repositories.
