Submission + - Shai Hulud 2.0 worm nibbling through npm supply chain (www.wiz.io)
BooleanMusic writes: In a rare glimpse into what might be happening constantly, a large-scale npm supply chain attack was uncovered on November 24, 2025. The campaign appears highly effective, exploiting the self-reinforcing nature of modern software development—like a snake devouring its own tail—to spread across repositories. Reported impact includes credential theft, exposure of internal system details, and other severe compromises.
While the attack references the earlier “Shai Hulud” campaign disclosed this year, it’s unclear whether the same actors are behind it.
While the attack references the earlier “Shai Hulud” campaign disclosed this year, it’s unclear whether the same actors are behind it.