top of page
perceptive_background_267k.jpg

Sha1-Hulud: The Second Coming - Zapier, ENS Domains, and Other Prominent NPM Packages Compromised

Published:

4 december 2025 om 19:41:42

Alert date:

5 december 2025 om 08:03:23

Source:

stepsecurity.io

Click to open the original link from this advisory

The Shai-Hulud campaign has returned with a second wave of attacks targeting prominent NPM packages. This supply chain attack has compromised packages associated with major organizations including Zapier and ENS Domains. The attack represents a significant escalation in NPM ecosystem targeting, affecting widely-used packages that could impact numerous downstream applications. This is a continuation of the previously identified Shai-Hulud campaign, indicating persistent threat actor activity in the JavaScript package ecosystem. The compromise of high-profile packages suggests potential for widespread impact across the development community.

Technical details

Mitigation steps:

Affected products:

NPM
Zapier
ENS Domains

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page