The second Shai-Hulud attack last week exposed around 400,000 raw secrets after infecting hundreds of packages in the NPM (Node Package Manager) registry and publishing stolen data in 30,000 GitHub repositories. Although just about 10,000 of the exposed secrets were verified as valid by the open-source TruffleHog scanning tool, researchers at cloud security platform Wiz say that more than 60% of the leaked NPM tokens were still valid as of December 1st. The Shai-Hulud threat emerged in mid-September, compromising 187 NPM packages with a self-propagating payload that identified account tokens using TruffleHog, injected a malicious script into the packages, and automatically published them on the platform. In the second attack, the malware impacted over 800 packages (counting all infected versions of a package) and included a destructive mechanism that wiped the victim’s home directory if certain conditions were met. Wiz researchers analyzing the leak of secrets that the Shai-Hulud 2.0 attack spread over 30,000 GitHub repositories, found that the following types of secrets have been exposed: Wiz notes that the malware used TruffleHog without the ‘-only-verified’ flag, meaning that the 400,000 exposed secrets match a known format and may not be valid or usable anymore. “While the secret data is extremely noisy and requires heavy deduplication efforts, it still contains hundreds of valid secrets, including cloud, NPM tokens, and VCS credentials,” explained Wiz. “To date, these c...
Shai-Hulud 2.0 NPM malware attack exposed up to 400,000 dev secrets
BleepingComputer
·Bill Toulas
·Published Dec 2, 2025
·Updated
Affected Software
1 affected component
npm package
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the Shai-Hulud 2.0 NPM malware attack that exposed approximately 400,000 developer secrets.
2
What security implications are discussed in the article?
The article highlights the risks of sensitive information exposure through compromised NPM packages and the potential for unauthorized access to valuable data.
3
What products or software are affected by this attack?
The attack primarily affects packages in the NPM (Node Package Manager) registry.
4
How many GitHub repositories were involved in the Shai-Hulud 2.0 attack?
The attack resulted in the publication of stolen data in around 30,000 GitHub repositories.
5
What was the scale of secrets exposed during the Shai-Hulud 2.0 attack?
The attack led to the exposure of nearly 400,000 raw developer secrets.