Second Wave of Sha1-Hulud Attack Hits Hundreds of NPM Packages

Sha1-Hulud Supply Chain Attack Compromises Hundreds of npm Packages, Steals Credentials, and Destroys Data if Exfiltration Fails

  • A new wave of supply chain attacks named Sha1-Hulud has compromised hundreds of npm packages between November 21 and 23, 2025.
  • The attack executes malicious code during the preinstall phase, targeting build and runtime environments.
  • The Malware steals credentials by scanning local machines and exfiltrates secrets from GitHub repositories.
  • In case of failure to steal credentials or establish control, the malware destroys user data, marking a significant escalation.
  • Over 25,000 repositories have been affected, prompting urgent recommendations to remove compromised packages and audit repositories for malicious workflows.

New reports have surfaced about a renewed supply chain attack campaign called Sha1-Hulud, which has infiltrated hundreds of npm packages over several days in late November 2025. The compromised packages were uploaded to the npm registry from November 21 to 23, according to detailed analyses by security firms including Aikido, HelixGuard, and others.

- Advertisement -

This campaign introduces a malicious variant that runs code in the preinstall stage of npm package deployment. Researchers from Wiz noted the expanded risk to build and runtime environments. The attack includes adding a preinstall script titled “setup_bun.js” to the package.json file, which stealthily installs or finds the Bun runtime environment and executes a malicious script called “bun_environment.js.”

The payload initiates two key workflows. First, it registers the infected computer as a self-hosted runner named “SHA1HULUD” and installs a GitHub Actions workflow (.github/workflows/discussion.yaml) containing an injection flaw. This workflow runs only on self-hosted runners and allows attackers to execute arbitrary commands by opening discussions in the GitHub repo. Second, it exfiltrates secrets stored in GitHub’s secrets section by uploading them as artifacts before deleting the workflow to hide evidence.

According to HelixGuard, the malware also runs the credential scanner TruffleHog. This tool searches local systems for sensitive data such as npm tokens, cloud credentials (AWS, GCP, Azure), and environment variables, which are then sent to the attackers.

Over 25,000 repositories linked to approximately 350 unique users have been affected, with new infections increasing steadily—about 1,000 additional repositories every 30 minutes, reported Wiz. The campaign continues the style of the earlier Shai-Hulud breach from September 2025 but may involve different threat actors.

- Advertisement -

A notable escalation described by Koi Security involves a destructive “wiper” function. If the malware fails to authenticate with GitHub, create repositories, retrieve tokens, or locate npm tokens, it erases all writable files in the user’s home directory. Security researchers Yuval Ronen and Idan Dardikman said, “If Sha1-Hulud is unable to steal credentials, obtain tokens, or secure any exfiltration channel, it defaults to catastrophic data destruction.”

Organizations are advised to scan endpoints for compromised npm packages, remove affected versions immediately, rotate all credentials, and closely audit repositories for suspicious workflows or branches under the .github/workflows/ directory, looking for files like shai-hulud-workflow.yml.

(This situation remains under investigation and details will be updated as they become available.)

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Altcoin Rotation: XRP, Solana Rally as Bitcoin Consolidates.

Selective altcoins, led by XRP and Solana, have outperformed majors amid market consolidation.Analysts describe...

XRP Could Reach $6.20 If Market Cap Equals Ethereum by 2027?

XRP rose sharply in 2025, topping $3 in January and reaching $3.65 in July.If...

Paradox Founder Linked to UK Illegal Weight-Loss Ring Probed

Fasial Tariq, co-founder of Paradox Metaverse, is linked to a UK industrial unit raided...

Institutions Ramp Up ETH Staking as SharpLink Yields Surge!!

SharpLink Gaming earned 10,657 ETH (about $33 million) in staking rewards over the past...

Evidence-Backed 2026 Cyber Forecast: Bitdefender on AI Risks

Data-driven webinar outlines which 2026 Cybersecurity predictions reflect real risk versus speculation.Ransomware is shifting...
- Advertisement -

Must Read

7 Best NFT Marketplaces for Every Need

Open Sea | Pianity | Foundation | Magic Eden | SuperRare | Rarible | Theta Drop | Other Platforms | About NFTs | FAQ...
Bitcoin (BTC) $ 91,050.00 0.71%
Ethereum (ETH) $ 3,112.31 0.44%
XRP (XRP) $ 2.12 0.70%
Bittensor (TAO) $ 290.54 3.71%
Polkadot (DOT) $ 2.09 1.86%
Cardano (ADA) $ 0.395461 1.14%
Chainlink (LINK) $ 13.23 0.33%
Hyperliquid (HYPE) $ 25.66 2.03%
Monero (XMR) $ 458.38 0.63%
Hedera (HBAR) $ 0.120666 0.42%
Toncoin (TON) $ 1.76 5.39%