Close Menu
  • Home
  • AI
  • Big Data
  • Cloud Computing
  • iOS Development
  • IoT
  • IT/ Cybersecurity
  • Tech
    • Nanotechnology
    • Green Technology
    • Apple
    • Software Development
    • Software Engineering

Subscribe to Updates

Get the latest technology news from Bigteetechhub about IT, Cybersecurity and Big Data.

    What's Hot

    Laurence Fournier Beaudry and Guillaume Cizeron are on the brink of a controversial Olympic ice dance gold

    February 11, 2026

    iOS 26, using Swift, how can I group multiple Liquid Glass buttons into a single pill view?

    February 11, 2026

    One platform for the Agentic AI era

    February 11, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Big Tee Tech Hub
    • Home
    • AI
    • Big Data
    • Cloud Computing
    • iOS Development
    • IoT
    • IT/ Cybersecurity
    • Tech
      • Nanotechnology
      • Green Technology
      • Apple
      • Software Development
      • Software Engineering
    Big Tee Tech Hub
    Home»Software Development»Shai-Hulud is back with a new campaign infecting more npm packages
    Software Development

    Shai-Hulud is back with a new campaign infecting more npm packages

    big tee tech hubBy big tee tech hubNovember 25, 2025013 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
    Follow Us
    Google News Flipboard
    Shai-Hulud is back with a new campaign infecting more npm packages
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    desert 4134918 1280desert 4134918 1280

    A new malicious campaign linked to the Shai-Hulud worm is making its way throughout the npm ecosystem. According to findings from Wiz, over 25,000 npm packages have been compromised and over 350 users have been impacted.

    Shai-Hulud was a worm that infected the npm registry back in September, and now a new worm spelled as Sha1-Hulud is appearing in the ecosystem again, though it is unclear at the time of writing whether the two worms were made by the same threat actor.

    Wiz and Aikido researchers have confirmed that Sha1-Hulud was uploaded to the npm ecosystem between November 21st and 23rd. They also say that projects from Zapier, ENS Domains, PostHog, and Postman were some of the ones that were trojanized, and newly compromised packages are still being discovered.

    Like Shai-Hulud, this new malware also steals developer secrets, though Garrett Calpouzos, principal security researcher at Sonatype, explained that the mechanism is slightly different, with two files instead of one. “The first checks for and installs a non-standard ‘bun’ JavaScript runtime, and then uses bun to execute the actual rather massive malicious source file that publishes stolen data to .json files in a randomly named GitHub repository,” he told SD Times.

    Wiz believes this preinstall-phase significantly increases the blast radius across build and runtime environments.

    Other differences, according to Aikido, are that it creates a repository of stolen data with a random name instead of a hardcoded name, can infect up to 100 packages instead of 20, and if it can’t authenticate with GitHub or npm it wipes all files in the user’s Home directory.

    The researchers from Wiz recommend that developers remove and replace compromised packages, rotate their secrets, audit their GitHub and CI/CD environments, and then harden their pipelines by restricting lifecycle scripts in CI/CD, limiting outbound network access from build systems, and using short-lived scoped automation tokens.

    Sonatype’s Calpouzos also said that the size and structure of the file confuses AI analysis tools because it is bigger than the normal context window, making it hard for LLMs to keep track of what they are reading. He explained that he tested this out by asking ChatGPT and Gemini to analyze it, and has been getting different results every time. This is because the models are searching for obvious malware patterns, such as calls to suspicious domains, and aren’t finding any, leading to the conclusion that the files are legitimate.

    “It’s a clever evolution. The attackers aren’t just hiding from humans, they’re learning to hide from machines too,” Calpouzos said.



    Source link

    Campaign infecting npm packages ShaiHulud
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    tonirufai
    big tee tech hub
    • Website

    Related Posts

    How to Build Solana Trading Bots

    February 10, 2026

    People don’t belong in the loop — They belong at the center

    February 10, 2026

    Is the craft dead? – Scott Hanselman’s Blog

    February 9, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Laurence Fournier Beaudry and Guillaume Cizeron are on the brink of a controversial Olympic ice dance gold

    February 11, 2026

    iOS 26, using Swift, how can I group multiple Liquid Glass buttons into a single pill view?

    February 11, 2026

    One platform for the Agentic AI era

    February 11, 2026

    An ice dance duo skated to AI music at the Olympics

    February 11, 2026
    About Us
    About Us

    Welcome To big tee tech hub. Big tee tech hub is a Professional seo tools Platform. Here we will provide you only interesting content, which you will like very much. We’re dedicated to providing you the best of seo tools, with a focus on dependability and tools. We’re working to turn our passion for seo tools into a booming online website. We hope you enjoy our seo tools as much as we enjoy offering them to you.

    Don't Miss!

    Laurence Fournier Beaudry and Guillaume Cizeron are on the brink of a controversial Olympic ice dance gold

    February 11, 2026

    iOS 26, using Swift, how can I group multiple Liquid Glass buttons into a single pill view?

    February 11, 2026

    Subscribe to Updates

    Get the latest technology news from Bigteetechhub about IT, Cybersecurity and Big Data.

      • About Us
      • Contact Us
      • Disclaimer
      • Privacy Policy
      • Terms and Conditions
      © 2026 bigteetechhub.All Right Reserved

      Type above and press Enter to search. Press Esc to cancel.