TF-MAL-js.shai_hulud
📛 Threat Title
Malware family: Shai-Hulud
Description
ThreatFox malware family `js.shai_hulud`. Printable name: Shai-Hulud.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
Shai-Hulud Shai-Hulud is a supply chain worm, first reported in September 2025, that spreads through code repositories, including GitHub and NPM packages. It exploits CI/CD pipeline dependencies to propagate to victims and poisons the supply chain by publishing malicious packages.
-
web:research.jfrog.com
Defending Against Shai-Hulud : The Complete Protection and Response Guide Defending your organization against the " Shai-Hulud " worm and its evolved variant, "Sha1- Hulud the second coming", requires immediate action and a systematic approach. This highly efficient, GitHub-weaponized exfiltration attack has compromised npm supply chains worldwide.
-
web:unit42.paloaltonetworks.com
Self-replicating worm " Shai-Hulud " has compromised hundreds of software packages in a supply chain attack targeting the npm ecosystem. We discuss scope and more.
-
web:windowsforum.com
Shai‑Hulud 2.0 is a watershed supply‑chain incident because it weaponizes the package lifecycle to execute earlier than most defenses expect, harvests high‑value cloud credentials, and automates propagation.
-
web:www.akamai.com
The next day, new GitHub repositories appeared to be hosting the source code of the malicious Shai-Hulud worm. In this blog post, we analyze the newly released malware , examine how this attack wave differs from earlier waves, and provide mitigation recommendations for maintainers and organizations.
-
web:www.bleepingcomputer.com
Threat actors earlier today published more than 600 malicious packages to the Node Package Manager (npm) index as part of a new Shai-Hulud supply-chain campaign.
-
web:www.microsoft.com
The Shai‑Hulud 2.0 supply chain attack represents one of the most significant cloud-native ecosystem compromises observed recently.
-
web:www.rescana.com
The true cost of Shai-hulud extends far beyond immediate remediation , exposing organizations to persistent credential theft, lateral movement, and the erosion of trust in the open-source software supply chain.
-
web:www.tenable.com
Shai-Hulud is the worm family . Mini Shai-Hulud is the current generation of that worm and the name TeamPCP uses for the active campaign. When did these campaigns start? The original Shai-Hulud worm appeared in September 2025 as the first self-replicating malware observed in the npm ecosystem.
-
web:www.wiz.io
Shai-Hulud is back, spreading an npm malware worm through thousands of GitHub repos. Learn the impact, attacker methods, and how to defend your supply chain.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.