HomeAtlasDashboardChartsReal valueResearchPersonsCatalogsBlockchainBubble MapGlobeQuantumAILeadershipLensesMethodologyGlossarySource ↗
Independent research & opinion. Gradings are automated / LLM-assisted and may contain errors or hallucinations; nothing here is a statement of fact, financial advice, or an accusation of wrongdoing by any party. Claims about identifiable people or organizations reflect public records + good-faith interpretation; intent is not inferred from association. Methodology & disclaimer.

Shai-Hulud npm worm (2025-26): self-replicating supply-chain compromise + the Mini variant

Shai-Hulud is a self-propagating npm worm: it steals a maintainer's publish token, injects a malicious install hook into all their packages, republishes an incremented patch, and repeats - turning the open-source dependency graph into a spreading medium. (This block also fixes a graph gap - the prior Shai-Hulud write-up was prose-only.)

Honest limits. Totals differ by vendor and evolved as detection continued (ranges shown, not single numbers); ultimate operator attribution is not established. GitHub - the exfiltration and propagation surface - is owned by Microsoft.

It marks the return of the worm at ecosystem scale, but through the software supply chain (registries + CI/CD + AI agents) rather than email (ILOVEYOU) or SMB (EternalBlue).

Sources: Palo Alto Unit42; eSentire; Zscaler; Arctic Wolf; Checkmarx; Cloud Security Alliance; Invicti/Lumific. Cross-refs: npm_Ecosystem, GitHub, Microsoft, Malware_Lineage.

← Research index · structured data: spec-shai-hulud-npm-worm.json · spec-shai-hulud-npm-worm.md