


Perceptive Security
SOC/SIEM Consultancy

Sha1-Hulud: The Second Coming - Zapier, ENS Domains, and Other Prominent NPM Packages Compromised
Published:
4 december 2025 om 19:41:42
Alert date:
5 december 2025 om 08:03:23
Source:
stepsecurity.io

The Shai-Hulud campaign has returned with a second wave of attacks targeting prominent NPM packages. This supply chain attack has compromised packages associated with major organizations including Zapier and ENS Domains. The attack represents a significant escalation in NPM ecosystem targeting, affecting widely-used packages that could impact numerous downstream applications. This is a continuation of the previously identified Shai-Hulud campaign, indicating persistent threat actor activity in the JavaScript package ecosystem. The compromise of high-profile packages suggests potential for widespread impact across the development community.
Technical details
Mitigation steps:
Affected products:
NPM
Zapier
ENS Domains
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.