Skip to main content
Black Friday Sale - Get 40% off Vantage
Published loading...Updated

Wormable npm attack returns as 25,000 repos spill secrets

The Shai-Hulud malware campaign has trojanized over 27,000 npm packages, exposing more than 25,000 GitHub repositories with stolen developer and CI/CD secrets, researchers said.

  • On November 23, Wiz researchers reported the Shai-Hulud malware had trojanized npm packages, with more than 25,000 repositories publishing secrets within three days and the campaign expanding beyond 27,000 packages.
  • Threat actors leveraged compromised maintainer accounts to publish modified legitimate packages by injecting malicious scripts into the package.json file, tracing back to the initial September variant of Shai-Hulud.
  • Technical analysis shows payloads include setup_bun.js and a 10MB bun_environment.js that execute during the pre-install stage, creating cloud.json and truffleSecrets.json before exfiltrating AWS, GCP, Azure, and GitHub credentials.
  • At publishing time, GitHub returned 27,600 search results and is deleting attacker repositories, but Wiz researchers noted 1,000 new repositories every 30 minutes complicate cleanup.
  • Npm announced it will revoke classic tokens on December 9, while GitHub is deprecating legacy tokens and security teams recommend rotating credentials, clearing npm cache, downgrading dependencies, and disabling postinstall scripts.
Insights by Ground AI

15 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news in on Monday, November 24, 2025.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal