• News/
  • https://www.theregister.com/2025/11/24/shai_hulud_npm_worm/

Shai-Hulud worm returns, belches secrets to 25K GitHub repos

The Register
·
Connor Jones
·
Published Nov 24, 2025
·
Updated

A self-propagating malware targeting node package managers (npm) is back for a second round, according to Wiz researchers who say that more than 25,000 developers had their secrets compromised within three days. The affected packages include those provided by Zapier, AsyncAPI, ENS Domains, PostHog, and Postman, several of which have thousands of weekly downloads. The campaign, dubbed "Shai-Hulud" for the frequent references to the Dune worm in published data, first emerged in September. The wormable malware spread via compromised npm packages. Once installed, it would scan infected hosts for AWS, GCP, Azure, and GitHub credentials before publishing them to users' own GitHub repositories. Wiz said the latest attacks, possibly launched by separate criminals, operate similarly to the first – scanning infected machines for secrets which the malware then publishes to victims' own repositories. As of September 24, more than 25,000 repositories had published their own secrets, and 1,000 more were being added every 30 minutes over "the last couple of hours," Wiz said on Monday morning. GitHub is actively deleting compromised repos, but the pace at which the worm is spreading makes cleanup a challenge. The attack borrows much from the infection chain of the initial September variant. The attackers gain access to npm maintainer accounts and publish trojanized versions of their packages, appearing to originate from the official source. Developers then unwittingly download and run the ma...

Read full article

Affected Software

6 affected components
npm npm
Zapier Zapier
asyncapi AsyncAPI
ENS Domains ENS Domains
PostHog PostHog
Postman Postman
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the primary focus of the article about the Shai-Hulud worm?

The article discusses the resurgence of the Shai-Hulud worm, a malware that targets Node Package Manager (npm) and has compromised secrets from over 25,000 developers.

2

What specific security risks are highlighted in the article regarding the Shai-Hulud worm?

The article emphasizes the risk of secret exposure and compromise of sensitive information from developers using affected npm packages.

3

Which software and platforms are mentioned as being affected by the Shai-Hulud worm?

Affected platforms include npm, Zapier, AsyncAPI, ENS Domains, PostHog, and Postman.

4

How quickly did the Shai-Hulud worm manage to compromise developer secrets according to the researchers?

The Shai-Hulud worm compromised secrets from over 25,000 developers within a span of just three days.

5

What is the significance of the Shai-Hulud worm's self-propagation capability?

Its self-propagation allows the worm to spread rapidly, increasing the scale and impact of the compromise across numerous repositories.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203