News

Self-replicating worm hits 180+ npm packages in (largely) automated supply chain attack

  • Zeljka Zorz--Help Net Security
  • published date: 2025-09-16 19:29:42 UTC

A potentially monumental supply chain attack is underway, thanks to a self-replicating worm-like payload that has been compromising packages published on the npm Registry. The worm has been dubbed “Shai-hulud” as it steals credentials from victims who run a c…

A potentially monumental supply chain attack is underway, thanks to a self-replicating worm-like payload that has been compromising packages published on the npm Registry. The worm has been dubbed “… [+4249 chars]