Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Happy Birthday, Shai-Hulud

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
964
Company Posts That Month
22
Language
English
Hacker News Points
-
Post removed?
No
Summary

One year after a malicious update to the widely used @ctrl/tinycolor package introduced Shai-Hulud, npm continues to face the consequences of the first known self-propagating worm in its ecosystem. The malware used legitimate secret-scanning software to steal npm, GitHub, and cloud credentials, establish persistence through GitHub Actions, and republish infected packages using victims’ tokens; later variants expanded execution to pre-install scripts, added destructive capabilities, and exploited short-lived CI OIDC tokens. Repeated campaigns through 2026 compromised hundreds of packages at a time, while TeamPCP open-sourced related code and promoted attacks through a contest, enabling broader reuse by multiple actors. Australian police arrested two alleged TeamPCP members in August 2026, though the original 2025 worm authors remain unidentified and should not be conclusively linked to the group. The incidents exposed persistent weaknesses in package publishing, token management, CI security, and install-script trust, prompting widespread credential rotations, dependency audits, and strengthened supply-chain security practices.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.