A terrifying and self -reproductive malwaere has infected NPM packages with more than 2 million downloads per week – here is how to stay safe


  • A new supply chain attack compromised at least 187 NPM packages, targeting developer’s secrets in software projects
  • The worm shai-hulud seeks to steal identification information, modify the packages and spread malware via github actions and npm tokens
  • Researchers warn that the number of compromised packages should grow

At least 187 malicious NPM packages were discovered, part of another major supply chain attack against software developers.

Socket safety researchers, Stepscurity and Aikido have all detected an ongoing campaign, apparently orchestrated by the same group that targeted NX several weeks ago.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top