{
  "id": 135087,
  "title": "Fast-Moving Shai-Hulud Attack Infects npm Packages with 2 Billion Monthly Downloads",
  "url": "https://urgent.news/2026/08/04/fast-moving-shai-hulud-attack-infects-npm-packages-with-2-billion",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-04T15:30:44.000Z",
  "source": {
    "name": "DevOps.com",
    "slug": "devops-com",
    "url": "https://devops.com/fast-moving-shai-hulud-attack-infects-npm-packages-with-2-billion-monthly-downloads/"
  },
  "original_language": "en",
  "account": "A supply-chain attack has compromised a large number of npm software packages, with combined monthly downloads exceeding 2 billion. The attack, which researchers are linking to the Shai-Hulud worm, involves stealing secrets and other information from victims' systems. The breach was carried out by compromising the GitHub account of a key-value storage library's maintainer and then pushing malicious files directly to the main branch, resulting in the release of infected versions to npm. Aikido Security and Endor Labs researchers have reported that the attack is spreading rapidly, with over 1,280 packages infected within a short period of time. The malware injects two files, setup.mjs and Math_Symbol.js, into affected packages, which automatically execute before a successful installation. setup.mjs downloads a JavaScript runtime and executes the real payload, Math_Symbol.js, which is an obfuscated file containing credential stealers. These stealers target various secret stores in victims' systems, such as npm and GitHub tokens, AWS credentials, Kubernetes secrets, HashiCorp Vault tokens, and Stripe and Slack tokens. The attack targets not only individual developers but also organizations, including Deliveroo, OneReach, ServiceTitan, Picsart, and Qlik. To mitigate the threat, organizations are advised to pin or roll back infected packages, rotate credentials, search lockfiles and CI logs for malicious versions, and use npm, yarn, and pnpm overrides for keyv, flat-cache, and file-entry-cache.",
  "summary": "Researchers at Aikido Security and Endor Labs are tracking a fast-spreading supply-chain attack that is compromising a wide range of npm software packages that combined have more than 2 billion installs a month and is stealing a wide range of secrets and other information. According to Ilyas Makari, malware researcher with Aikido, the bad actor […]",
  "key_points": [
    "Shai-Hulud worm infects npm packages with 2 billion monthly downloads",
    "Attackers compromise GitHub maintainer's account to push malicious files",
    "Infected packages inject setup.mjs and MathSymbol.js to steal secrets"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}