Home / Thinking / Blog / npm Under Attack!
September 19, 2025

Urgent Security Advisory – “Shai-Hulud” npm Worm

Protection shield for npm projects with a purple worm attacking the npm logo. Warning about the Shai-Hulud worm attack. Protect your npm projects now from the supply-chain attack.

DAVIES MEYER is issuing an urgent advisory about a widespread npm supply-chain compromise. 

 

A self-propagating malware campaign, commonly called Shai-Hulud, has been observed trojanizing npm packages by compromising maintainer credentials and inserting post-install payloads that harvest tokens and secrets.

Impact & Behavior

 

  • Propagation: Maintainer accounts are compromised; malicious packages are published; credentials are stolen and used to compromise additional packages automatically.

 

  • Malicious actions: Post-install scripts scan for secrets (npm tokens, GitHub PATs, cloud keys) and exfiltrate them; GitHub workflows are injected for persistence.

     

  • Scope: Dozens to hundreds of packages are impacted, including high-traffic ones like @ctrl/tinycolor.

Recommended Actions

 

1. Audit and remove affected packages; rebuild from clean sources.

 

2. Rotate/revoke all potentially compromised credentials.

 

3. Review GitHub repos/workflows for suspicious activity.

 

4. Enforce MFA, least privilege, and stronger CI/CD controls.

Next Steps

DAVIES MEYER continues to monitor vendor feeds (Unit 42, Trend Micro, Wiz, Socket, JFrog) and will publish updates with indicators of compromise (IOCs).

 

👉 If your team needs immediate support to audit dependencies, rotate credentials, or secure build pipelines, please contact DAVIES MEYER’s security team. We are ready to assist with urgent checks, and remediation.

Get in Touch

Let’s Create Something Unique Together!

Explore how DAVIES MEYER can elevate your brand with our holistic digital marketing solutions.

Nick Meyer
Nick Meyer CEO at DAVIES MEYER
Name missing
Email invalid Email invalid
Message not correct. Please enter at least 10 characters! Message not correct. Please enter at least 10 characters!
Please upload a PDF document with a maximum size of 10 MB. The uploaded file exceeds the maximum allowed size of 10 MB or is of an incorrect type. Please remove the file and try again.
Please accept terms and conditions!

Thank you for contacting us!

Fact Flash

Did you know that ...

... Germany's OMR Festival, held annually in Hamburg, attracts thousands of digital marketing enthusiasts and industry professionals from around the world, making it one of the largest gatherings of its kind in Europe?