# npm ecosystem supply chain attacks

> Live situation record from CLSTR: https://clstr.news/situations/npm-ecosystem-supply-chain-attacks
> Updated: 2026-08-10T22:08:59.000Z. Sources: 7. Developments: 2.

A significant software supply chain attack has targeted the npm ecosystem, affecting hundreds of packages. Initial reports identified a wave of the ‘Shai-Hulud worm’ that had infected over 440 packages, including widely used libraries like keyv and flat-cache. This malware was designed to steal credentials such as GitHub tokens, SSH keys, and cloud access data by infiltrating development processes and CI/CD workflows.

Subsequent findings expanded the scope of the campaign, identifying nearly 800 malicious packages. The attack utilizes AI-generated or typo-squatted names to evade detection and deploys Remote Access Trojans (RAT) and infostealers. Research suggests North Korean-linked threat actors are involved, employing a sophisticated command-and-control mechanism that uses Ethereum transactions as a ‘public dead drop’ to retrieve infrastructure IP addresses, making the malware more resilient to traditional blocking methods.

## Timeline

### 2026-08-10: npm registry targeted by massive malware campaign

A major npm supply chain attack involving nearly 800 malicious packages has been discovered, with North Korean-linked actors using Ethereum transactions for stealthy command-and-control operations.

5 sources. https://clstr.news/cluster/npm-registry-targeted-by-massive-malware-campaign

### 2026-08-10: Shai-Hulud worm targets npm ecosystem via supply chain attacks

The Shai-Hulud worm has infected over 440 npm packages, including libraries with billions of monthly downloads, threatening global software supply chains by stealing developer credentials.

2 sources. https://clstr.news/cluster/shai-hulud-worm-targets-npm-ecosystem-via-supply-chain-attacks

---
Cite as: npm ecosystem supply chain attacks. CLSTR, https://clstr.news/situations/npm-ecosystem-supply-chain-attacks
