s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-js.shai_hulud

📛 Threat Title

Malware family: Shai-Hulud

Category: Shai-Hulud First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.shai_hulud`. Printable name: Shai-Hulud.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:attack.mitre.org

    Shai-Hulud Shai-Hulud is a supply chain worm, first reported in September 2025, that spreads through code repositories, including GitHub and NPM packages. It exploits CI/CD pipeline dependencies to propagate to victims and poisons the supply chain by publishing malicious packages.

  • web:research.jfrog.com

    Defending Against Shai-Hulud : The Complete Protection and Response Guide Defending your organization against the " Shai-Hulud " worm and its evolved variant, "Sha1- Hulud the second coming", requires immediate action and a systematic approach. This highly efficient, GitHub-weaponized exfiltration attack has compromised npm supply chains worldwide.

  • web:unit42.paloaltonetworks.com

    Self-replicating worm " Shai-Hulud " has compromised hundreds of software packages in a supply chain attack targeting the npm ecosystem. We discuss scope and more.

  • web:windowsforum.com

    Shai‑Hulud 2.0 is a watershed supply‑chain incident because it weaponizes the package lifecycle to execute earlier than most defenses expect, harvests high‑value cloud credentials, and automates propagation.

  • web:www.akamai.com

    The next day, new GitHub repositories appeared to be hosting the source code of the malicious Shai-Hulud worm. In this blog post, we analyze the newly released malware , examine how this attack wave differs from earlier waves, and provide mitigation recommendations for maintainers and organizations.

  • web:www.bleepingcomputer.com

    Threat actors earlier today published more than 600 malicious packages to the Node Package Manager (npm) index as part of a new Shai-Hulud supply-chain campaign.

  • web:www.microsoft.com

    The Shai‑Hulud 2.0 supply chain attack represents one of the most significant cloud-native ecosystem compromises observed recently.

  • web:www.rescana.com

    The true cost of Shai-hulud extends far beyond immediate remediation , exposing organizations to persistent credential theft, lateral movement, and the erosion of trust in the open-source software supply chain.

  • web:www.tenable.com

    Shai-Hulud is the worm family . Mini Shai-Hulud is the current generation of that worm and the name TeamPCP uses for the active campaign. When did these campaigns start? The original Shai-Hulud worm appeared in September 2025 as the first self-replicating malware observed in the npm ecosystem.

  • web:www.wiz.io

    Shai-Hulud is back, spreading an npm malware worm through thousands of GitHub repos. Learn the impact, attacker methods, and how to defend your supply chain.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.