• News/
  • https://www.bleepingcomputer.com/news/security/shai-hulud-20-npm-malware-attack-exposed-up-to-400-000-dev-secrets/

Shai-Hulud 2.0 NPM malware attack exposed up to 400,000 dev secrets

BleepingComputer
·
Bill Toulas
·
Published Dec 2, 2025
·
Updated

The second Shai-Hulud attack last week exposed around 400,000 raw secrets after infecting hundreds of packages in the NPM (Node Package Manager) registry and publishing stolen data in 30,000 GitHub repositories. Although just about 10,000 of the exposed secrets were verified as valid by the open-source TruffleHog scanning tool, researchers at cloud security platform Wiz say that more than 60% of the leaked NPM tokens were still valid as of December 1st. The Shai-Hulud threat emerged in mid-September, compromising 187 NPM packages with a self-propagating payload that identified account tokens using TruffleHog, injected a malicious script into the packages, and automatically published them on the platform. In the second attack, the malware impacted over 800 packages (counting all infected versions of a package) and included a destructive mechanism that wiped the victim’s home directory if certain conditions were met. Wiz researchers analyzing the leak of secrets that the Shai-Hulud 2.0 attack spread over 30,000 GitHub repositories, found that the following types of secrets have been exposed: Wiz notes that the malware used TruffleHog without the ‘-only-verified’ flag, meaning that the 400,000 exposed secrets match a known format and may not be valid or usable anymore. “While the secret data is extremely noisy and requires heavy deduplication efforts, it still contains hundreds of valid secrets, including cloud, NPM tokens, and VCS credentials,” explained Wiz. “To date, these c...

Read full article

Affected Software

1 affected component
npm package
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the Shai-Hulud 2.0 NPM malware attack that exposed approximately 400,000 developer secrets.

2

What security implications are discussed in the article?

The article highlights the risks of sensitive information exposure through compromised NPM packages and the potential for unauthorized access to valuable data.

3

What products or software are affected by this attack?

The attack primarily affects packages in the NPM (Node Package Manager) registry.

4

How many GitHub repositories were involved in the Shai-Hulud 2.0 attack?

The attack resulted in the publication of stolen data in around 30,000 GitHub repositories.

5

What was the scale of secrets exposed during the Shai-Hulud 2.0 attack?

The attack led to the exposure of nearly 400,000 raw developer secrets.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203