Davies Meyer – home
    Back to Blog
    Agency

    Shai-Hulud: lessons from the npm attack of 2025

    September 19, 2025
    3 min read
    DAVIES MEYER Team
    Shai-Hulud: lessons from the npm attack of 2025

    A review of the first Shai-Hulud in September 2025: compromised packages, stolen credentials and the limits of automated security checks.

    *Archive article dated September 19, 2025. Reviewed and updated on September 8, 2026. This article covers the first Shai-Hulud of September 2025; it is not a current alert or an all-clear.*

    What happened

    Shai-Hulud spread through compromised npm packages. Malicious code could run during installation, steal credentials and misuse them to publish further packages. GitHub confirmed compromised maintainer accounts and removed affected packages. The original Wiz investigation describes secret theft and propagation through accessible npm tokens.

    What an affected team needs to investigate

    A known vulnerability in a dependency and an already compromised development environment are different problems. Updating a version alone does not establish whether credentials were stolen.

    A concrete suspicion belongs in an incident response process: isolate affected systems, preserve evidence, revoke exposed credentials and replace them from a clean environment. Package versions, installation times, build logs and suspicious repository changes help determine the scope. The appropriate response depends on the actual exposure.

    What npm audit does

    `npm audit` checks configured dependencies for known vulnerabilities. A report without findings does not prove that a system is free of malicious code or stolen credentials. `npm audit fix` performs installation steps, so it is not a universal first response on a potentially compromised environment. Updates and recovery require review and testing.

    What this means for digital projects

    Dependencies need clear ownership, traceable changes and verifiable build processes. Security review is part of website quality alongside design and usability. For a current incident, use the current guidance from maintainers and your security team.

    Sources

    Share this article:

    Loading related terms…

    All Terms

    Ready for your next project?

    Let's discuss your marketing challenges and develop solutions together.

    Get in touch
    CMO Newsletter

    Bekomme solche Insights jede Woche.

    Strategische Marketing-Insights für CMOs — kein Fluff, kein Spam.

    Mit der Anmeldung stimmst du unserer Datenschutzerklärung zu.