• News/
  • https://www.bleepingcomputer.com/news/security/shai-hulud-malware-infects-500-npm-packages-leaks-secrets-on-github/

Shai-Hulud malware infects 500 npm packages, leaks secrets on GitHub

BleepingComputer
·
Bill Toulas
·
Published Nov 24, 2025
·
Updated

Hundreds of trojanized versions of well-known packages such as Zapier, ENS Domains, PostHog, and Postman have been planted in the npm registry in a new Shai-Hulud supply-chain campaign. The malicious packages have been added to NPM (Node Package Manager) over the weekend to steal developer and continuous integration and continuous delivery (CI/CD) secrets. The data is automatically posted on GitHub in encoded form. At publishing time, GitHub returned 27,600 results corresponding to entries related to the recent attack. When the Shai-Hulud malware first appeared in the npm space in mid-September, and it compromised 187 packages with a self-propagating payload that used the TruffleHog tool to steal developer secrets. The threat actor automatically downloaded legitimate packages, modified the package.json file to inject a malicious script, and then published them on npm using compromised maintainer accounts. Charlie Eriksen, malware researcher at developer-focused security platform Aikido Security, discovered the new campaign earlier today, when there were 105 trojanized packages with Shai-Hulud indicators. Since then, the number grew to 492, counting only the package names. Later, the researcher warned that the secrets stolen in the supply-chain attack were leaked on GitHub. However, the campaign has grown exponentially to more than 27,000 malicious packages. Threat researchers at Wiz cloud security platform discovered around 350 unique maintainer accounts used in the campaign...

Read full article

Affected Software

5 affected components
npm Node Package Manager
Zapier Zapier
ENS Domains ENS Domains
PostHog PostHog
Postman Postman
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the discovery of Shai-Hulud malware infecting 500 npm packages and leaking secrets on GitHub.

2

What security implications are discussed?

The article highlights the risks posed by trojanized npm packages that can compromise security by leaking sensitive information.

3

What products or software are affected?

The affected software includes popular npm packages like Zapier, ENS Domains, PostHog, and Postman.

4

How many npm packages were infected by Shai-Hulud malware?

Shai-Hulud malware has infected 500 npm packages according to the article.

5

What type of attack does Shai-Hulud represent?

Shai-Hulud represents a supply-chain attack, specifically targeting the npm package ecosystem.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203