Shai-Hulud is a self-propagating software supply-chain threat cluster centered on malicious npm package compromises that began in September 2025 and later evolved into broader multi-wave and multi-ecosystem activity. It is widely characterized as the first truly self-propagating npm worm. The campaign initially spread by compromising popular JavaScript packages, harvesting secrets from developer and CI/CD environments, and then using stolen publishing credentials and repository access to inject malicious code into additional packages controlled by affected maintainers. More than 500 npm packages were reported compromised in early waves, with later reporting describing recurring variants and related offshoots such as Shai-Hulud 2.0 and Mini Shai-Hulud. Some reporting also places the activity cluster in an evolutionary line leading toward the modular Miasma framework, although separate incidents that merely resemble Shai-Hulud have also been explicitly assessed as unattributed or false-flagged. Core tradecraft associated with Shai-Hulud includes credential theft, secret reconnaissance, exfiltration, persistence, and automated propagation through trusted developer infrastructure. Documented behavior includes harvesting GitHub personal access tokens, npm tokens, cloud credentials, CI/CD secrets, and other sensitive material from local environments, repositories, workflow logs, and metadata services. The malware has used tools and logic comparable to TruffleHog-style secret scanning, abuse of GitHub Actions and self-hosted runners, malicious workflow injection, repository modification, and republishing of trojanized packages using compromised maintainer rights or trusted publishing flows. Exfiltration has repeatedly leveraged GitHub itself, including attacker-created repositories, commits, and workflow channels, allowing the actor to blend command-and-control and data theft into legitimate developer traffic. Later variants expanded the engineering sophistication of the campaign. Reported enhancements across subsequent waves include Bun-based staging and execution, modular dispatch and payload architecture, dead-drop command retrieval through public GitHub artifacts, persistence through developer-environment hooks and operating-system autostart mechanisms, and abuse of trusted automation identities for commit forgery or persona spoofing. Some variants also targeted AI-assisted developer tooling and editor configuration files to gain execution when repositories were opened or developer sessions started. A November 2025 wave reportedly added a destructive fallback that attempted to erase user data when useful credentials could not be found, indicating that some branches of the activity moved beyond pure credential theft into destructive behavior. Shai-Hulud primarily targets software maintainers, developer workstations, CI/CD runners, and organizations that depend on high-trust open-source packages. Victim environments have included npm package maintainers, GitHub repositories, and cloud-connected build systems. The campaign’s operational objective is best understood as theft of credentials and privileged access that can be reused for further compromise and propagation across software ecosystems. While multiple later incidents have been described as Shai-Hulud-like because they share propagation patterns, GitHub-centric exfiltration, or Bun-based loaders, only directly attributed activity should be considered part of the Shai-Hulud cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named npm worm activity associated with a software supply-chain compromise affecting popular npm packages. The operation uses compromised maintainer access to publish malicious package versions, steals cloud and developer credentials, republishes trojanized packages using stolen tokens/OIDC trusted publishing, stages exfiltrated data in GitHub repositories, and establishes persistence via developer tooling and OS autostart mechanisms.
Referenced only for comparison; the article explicitly says the malware is not attributed to this campaign.
Named as a self-propagating npm malware/worm campaign used as comparative context for the evolution of npm supply-chain threats; not directly tied in the content to the main axios incident attribution.
Conducted npm supply-chain compromise campaigns by trojanizing packages, harvesting GitHub/npm/cloud credentials, propagating automatically across maintainer-owned packages, exfiltrating secrets via GitHub workflows/webhooks, and in a later wave adding destructive file-wiping behavior when token theft failed.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.