Follow ZDNET: Add us as a preferred source on Google. For those of you who aren't Dune fans, Shai-Hulud are the giant sandworms of the desert planet Arrakis. You do not want to get in their way. Now, it's also the name of a self-replicating worm that compromised at least 180 npm packages, and perhaps as many as 500 of them. This is a major security crisis for anyone who programs in JavaScript and the JavaScript runtime environment Node.js. JavaScript, by the way, is one of the most popular programming languages. This supply chain attack hits pretty much all JavaScript developers. Also: This 2FA phishing scam pwned a developer - and endangered billions of npm downloads That's because Node Package Manager (npm) is JavaScript's default package manager and software registry. It enables developers to install, manage, and share packages -- prebuilt pieces of reusable code called modules -- that their JavaScript or Node.js projects depend on. Npm is the largest such open-source package library. Essentially, everyone who uses JavaScript uses it. Npm also has a horrible security track record. Month after month, year after year, hackers have successfully inserted malicious code into npm modules. This, in turn, means that corrupted code is automatically introduced into JavaScript-based programs used by end users. The most recent example of this was a week ago, when a phishing attack compromised 18 packages that were downloaded two billion times a week. This week's attack is much worse. ...
5 ways to spot software supply chain attacks and stop worms - before it's too late
ZDNet
·Steven Vaughan-Nichols
·Published Sep 19, 2025
·Updated
Affected Software
1 affected component
npm Node Package Manager