top of page
perceptive_background_267k.jpg

Shai-Hulud 2.0 Supply Chain Attack: 25K+ Repos Exposing Secrets

Published:

24 November 2025 at 10:27:46

Alert date:

5 December 2025 at 08:03:23

Source:

wiz.io

Click to open the original link from this advisory

Major supply chain attack campaign targeting npm packages affecting over 25,000 repositories across approximately 350 unique users. The Shai-Hulud campaign involves malicious npm packages designed to expose and steal secrets from affected repositories. This represents a significant ongoing threat to the JavaScript/Node.js ecosystem with widespread impact across the development community. Organizations using npm packages should immediately audit their dependencies and scan for compromised packages. The scale of this attack demonstrates the critical vulnerability of supply chain dependencies in modern software development.

Technical details

Mitigation steps:

Affected products:

npm packages
JavaScript repositories
Node.js ecosystem

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page