CyberzSOC

Publication detail
← Back to advisories & guidance

Widespread Supply Chain Compromise Impacting npm Ecosystem ↗ source

September 23, 2025 CISA Alert

Summary

CISA is releasing this Alert to provide guidance in response to a widespread software supply chain compromise involving the world’s largest JavaScript registry, npmjs.com. A self-replicating worm—publicly known as “Shai-Hulud”—has compromised over 500 packages. [i] After gaining initial access, the malicious cyber actor deployed malware that scanned the environment for sensitive credentials. The cyber actor then targeted GitHub Personal Access Tokens (PATs) and application programming interface (API) keys for cloud services, including Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure. [ii] Exfiltrated the harvested credentials to an endpoint controlled by the actor. Uploaded the credentials to a public repository named Shai-Hulud via the GitHub/user/repos API. Leveraged an automated process to rapidly spread by authenticating to the npm registry as the compromised developer, injecting code into other packages, and publishing compromised versions to the registry. [iii] Conduct a dependency review of all software leveraging the npm package ecosystem. Check for package-lock.json or yarn.lock files to identify affected packages, including those nested in dependency trees.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.