< Back to all clusters
[TECHNOLOGY] · Germany · 2 sources

started · updated

Shai-Hulud worm targets npm ecosystem via supply chain attacks

A new wave of the Shai-Hulud worm is targeting the npm ecosystem, creating significant risks for global software supply chains. Since August 4, 2026, more than 440 packages have been identified as infected. This includes widely used libraries such as keyv, cacheable, and flat-cache, which collectively account for over two billion monthly downloads.

The worm operates by infiltrating the development process. Once a developer installs a compromised package, the malware can steal credentials, including npm and GitHub tokens, cloud access data, SSH keys, and Kubernetes or Vault credentials. This allows the worm to spread autonomously through code repositories, cloud infrastructure, and automated CI/CD workflows.

In response to the threat, Dortmund-based Cybersense GmbH has released an early detection tool designed to identify suspicious activities on developer machines and within automated build and delivery processes.

Entities

Cybersense GmbH · GitHub · npm