top of page
perceptive_background_267k.jpg

Shai-Hulud: Self-Replicating Worm Compromises 500+ NPM Packages

Published:

23 november 2025 om 12:53:12

Alert date:

5 december 2025 om 08:03:23

Source:

stepsecurity.io

Click to open the original link from this advisory

The Shai-Hulud worm represents the first successful worm attack in the NPM ecosystem, infecting over 500 packages including @ctrl/tinycolor. The malware demonstrates sophisticated capabilities including credential harvesting for AWS, GCP, and Azure using TruffleHog tools. It establishes persistence through GitHub Actions backdoors and exhibits self-replicating behavior by automatically spreading to other maintainer packages. This marks an unprecedented self-propagating supply chain attack that leverages the interconnected nature of the NPM package ecosystem. The worm's ability to harvest cloud credentials and maintain persistence through CI/CD pipelines represents a significant escalation in supply chain attack sophistication.

Technical details

Mitigation steps:

Affected products:

NPM
@ctrl/tinycolor
GitHub Actions

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page