A self-propagating malware targeting node package managers (npm) is back for a second round, according to Wiz researchers who say that more than 25,000 developers had their secrets compromised within three days. The affected packages include those provided by Zapier, AsyncAPI, ENS Domains, PostHog, and Postman, several of which have thousands of weekly downloads. The campaign, dubbed "Shai-Hulud" for the frequent references to the Dune worm in published data, first emerged in September. The wormable malware spread via compromised npm packages. Once installed, it would scan infected hosts for AWS, GCP, Azure, and GitHub credentials before publishing them to users' own GitHub repositories. Wiz said the latest attacks, possibly launched by separate criminals, operate similarly to the first – scanning infected machines for secrets which the malware then publishes to victims' own repositories. As of September 24, more than 25,000 repositories had published their own secrets, and 1,000 more were being added every 30 minutes over "the last couple of hours," Wiz said on Monday morning. GitHub is actively deleting compromised repos, but the pace at which the worm is spreading makes cleanup a challenge. The attack borrows much from the infection chain of the initial September variant. The attackers gain access to npm maintainer accounts and publish trojanized versions of their packages, appearing to originate from the official source. Developers then unwittingly download and run the ma...
Shai-Hulud worm returns, belches secrets to 25K GitHub repos
The Register
·Connor Jones
·Published Nov 24, 2025
·Updated
Affected Software
6 affected components
npm npm
Zapier Zapier
asyncapi AsyncAPI
ENS Domains ENS Domains
PostHog PostHog
Postman Postman
Frequently Asked Questions
1
What is the primary focus of the article about the Shai-Hulud worm?
The article discusses the resurgence of the Shai-Hulud worm, a malware that targets Node Package Manager (npm) and has compromised secrets from over 25,000 developers.
2
What specific security risks are highlighted in the article regarding the Shai-Hulud worm?
The article emphasizes the risk of secret exposure and compromise of sensitive information from developers using affected npm packages.
3
Which software and platforms are mentioned as being affected by the Shai-Hulud worm?
Affected platforms include npm, Zapier, AsyncAPI, ENS Domains, PostHog, and Postman.
4
How quickly did the Shai-Hulud worm manage to compromise developer secrets according to the researchers?
The Shai-Hulud worm compromised secrets from over 25,000 developers within a span of just three days.
5
What is the significance of the Shai-Hulud worm's self-propagation capability?
Its self-propagation allows the worm to spread rapidly, increasing the scale and impact of the compromise across numerous repositories.