Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential Theft
These articles are AI-generated summaries. Please check the original sources for full details.
Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential Theft
A new supply chain attack named Sha1-Hulud has compromised over 25,000 GitHub repositories by injecting malicious npm packages. The attack exploits preinstall scripts to steal cloud credentials and, in some cases, wipe developer home directories.
Why This Matters
The attack highlights the fragility of npm’s trust model, where malicious actors compromise legitimate packages to execute code during installation. Unlike idealized secure systems, real-world supply chains are vulnerable to tampering, with this campaign leveraging preinstall hooks to bypass traditional security checks. Wiz reports 25,000+ repositories affected, with 1,000 new infections every 30 minutes, escalating risks for cloud infrastructure.
Key Insights
- “25,000+ repositories compromised, 2025”: Wiz researchers identified 350 unique users impacted.
- “Preinstall scripts for credential theft”: Attackers added
setup_bun.jsto package.json to runbun_environment.js, stealing secrets via TruffleHog. - “Docker-based root access attempts”: Malware uses Docker to mount host filesystems and gain passwordless root access.
Practical Applications
- Use Case: npm package maintainers must audit preinstall scripts for unauthorized modifications.
- Pitfall: Failing to rotate credentials after a breach can lead to prolonged exfiltration or destructive payloads.
References:
Continue reading
Next article
ShadowPad Malware Exploits WSUS Vulnerability for System Access
Related Content
npm Worm Shai-Hulud Strikes Again, Compromising 27,000 GitHub Repos
The Shai-Hulud npm worm resurfaces, stealing 3,760 valid secrets from 27,000 GitHub repositories in a supply chain attack.
Clinejection: How Prompt Injection Compromised AI Coding Tools for 4,000 Developers
The Clinejection attack turned Cline's GitHub Actions bot into a weapon, installing rogue agents on 4,000 developer machines via malicious npm updates in February 2026.
Shai-Hulud v2 Spreads From npm to Maven, as Campaign Exposes Thousands of Secrets
Shai-Hulud v2 breached npm and Maven, exposing 11,858 secrets across 28,000+ repositories.