Daily Dark Web
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
Daily Dark Web
No Result
View All Result
Home Vulnerability

Shai-Hulud Worm Infects Over 500 NPM Packages in Sophisticated Supply Chain Attack

September 17, 2025
Reading Time: 4 mins read
Shai-Hulud Worm Infects Over 500 NPM Packages in Sophisticated Supply Chain Attack

A widespread and sophisticated supply chain attack is currently unfolding within the Node Package Manager (npm) ecosystem, with a self-replicating worm “Shai-Hulud” compromising more than 500 popular packages, including some maintained by cybersecurity firm CrowdStrike. This worm-like malware is designed to steal credentials, such as npm and GitHub tokens, as well as cloud service keys, from developers and then use those credentials to spread itself to other packages, creating a cascading effect throughout the software supply chain.

The attack, which appears to be linked to a previous compromise in late August, employs a legitimate secret-scanning tool to find sensitive information on infected developer machines. Once credentials are stolen, the malware exfiltrates them to publicly accessible GitHub repositories. The worm then uses any compromised npm tokens to publish new, malicious versions of other packages maintained by the infected developer, allowing it to propagate automatically and rapidly expand its reach. This autonomous replication marks a significant evolution in supply chain attack techniques.

The data targeted by the malware includes:

  • Developer npm credentials
  • API Keys
  • Database passwords
  • Private keys
  • Other secrets stored in project environment files

Security researchers are actively investigating the full extent of the “Shai-Hulud” worm’s impact, urging developers to take immediate action. This includes revoking any potentially compromised credentials, auditing their projects for malicious dependencies, and removing any of the affected packages from their environments. The incident highlights the critical need for enhanced security measures and vigilance in the open-source software ecosystem, as the worm’s ability to spread without human intervention poses a severe and ongoing threat to developers and organizations worldwide.

Affected Packages:

@ahmedhfarag/[email protected]
@ahmedhfarag/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@art-ws/[email protected]
@crowdstrike/[email protected]
@crowdstrike/[email protected]
@crowdstrike/[email protected]
@crowdstrike/[email protected]
@crowdstrike/[email protected]
@crowdstrike/[email protected]
@crowdstrike/[email protected]
@crowdstrike/[email protected]
@crowdstrike/[email protected]
@crowdstrike/[email protected]
@crowdstrike/[email protected]
@crowdstrike/[email protected]
@crowdstrike/[email protected]
@crowdstrike/[email protected]
@crowdstrike/[email protected]
@crowdstrike/[email protected]
@crowdstrike/[email protected]
@crowdstrike/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@ctrl/[email protected]
@hestjs/[email protected]
@hestjs/[email protected]
@hestjs/[email protected]
@hestjs/[email protected]
@hestjs/[email protected]
@hestjs/[email protected]
@hestjs/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nativescript-community/[email protected]
@nexe/[email protected]
@nexe/[email protected]
@nexe/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@nstudio/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@operato/[email protected]
@teselagen/[email protected]
@teselagen/[email protected]
@teselagen/[email protected]
@teselagen/[email protected]
@teselagen/[email protected]
@teselagen/[email protected]
@teselagen/[email protected]
@teselagen/[email protected]
@teselagen/[email protected]
@teselagen/[email protected]
@teselagen/[email protected]
@teselagen/[email protected]
@teselagen/[email protected]
@teselagen/[email protected]
@teselagen/[email protected]
@thangved/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@things-factory/[email protected]
@tnf-dev/[email protected]
@tnf-dev/[email protected]
@tnf-dev/[email protected]
@tnf-dev/[email protected]
@tnf-dev/[email protected]
@ui-ux-gang/[email protected]
@yoobic/[email protected]
@yoobic/[email protected]
@yoobic/[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]

ShareTweet

Related Posts

CPUID Website Compromised: CPU-Z and HWMonitor Serve Malware
Vulnerability

CPUID Website Compromised: CPU-Z and HWMonitor Serve Malware

April 10, 2026
Axios npm Package Compromised in Supply Chain Attack
Vulnerability

Axios npm Package Compromised in Supply Chain Attack

March 31, 2026
Critical Figma MCP Server Flaw Allows Remote Code Execution
Vulnerability

Critical Figma MCP Server Flaw Allows Remote Code Execution

October 8, 2025
Oracle Patches CVE−2025−61882
Vulnerability

Oracle Patches CVE−2025−61882

October 6, 2025
WinRAR Zero-Day RCE Vulnerability Allegedly for Sale for $65,000
Vulnerability

WinRAR Zero-Day RCE Vulnerability Allegedly for Sale for $65,000

September 8, 2025
Atomic and Exodus Crypto Wallets at Risk from Deceptive npm Package
Vulnerability

Atomic and Exodus Crypto Wallets at Risk from Deceptive npm Package

September 2, 2025
Next Post
Spanish Airline Helity Copter Airlines Allegedly Breached, 2 Million Records For Sale

Spanish Airline Helity Copter Airlines Allegedly Breached, 2 Million Records For Sale

Over 1 Million Records of Poste Italiane Customers Allegedly Leaked in Data Breach

Over 1 Million Records of Poste Italiane Customers Allegedly Leaked in Data Breach

Recommended Stories

Alleged Access to a Cryptocurrency Exchange

Alleged Access to a Cryptocurrency Exchange

June 14, 2024
Threat Actor Allegedly Leaks 70 GB of KYC Data from CredRight

Threat Actor Allegedly Leaks 70 GB of KYC Data from CredRight

June 28, 2024
NP3 Benefícios Data Breach Exposes Customer and Driver Data

NP3 Benefícios Data Breach Exposes Customer and Driver Data

September 19, 2025

Popular Stories

  • SudamericaData Breach Exposes Over 1TB of Argentine Records

    SudamericaData Breach Exposes Over 1TB of Argentine Records

    0 shares
    Share 0 Tweet 0
  • Threat Actor Claims Sale of Dell Database Containing 49 Million Customer Records

    0 shares
    Share 0 Tweet 0
  • SUUMO, CHINTAI, At Home, HOME’S Suffer Data Breach

    0 shares
    Share 0 Tweet 0
  • Financial Tech Giant SilverLake Axis Allegedly Breached – 423GB of Data for Sale

    0 shares
    Share 0 Tweet 0
  • Telekom Serbia Investigates Leak of 160,000 Customer Records

    0 shares
    Share 0 Tweet 0
Daily Dark Web

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

No Result
View All Result
  • About Us
  • Home
  • Newsletter
  • Privacy Policy

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?