
Itamar Sher
November 26, 2025
Shai-Hulud: The Second Coming Hits npm Users
Once again, the npm supply chain has been compromised. On November 24th, a sophisticated attack that borrows techniques from the Shai-Hulud malware used in the npm hijacking this past September was discovered.This version is even more dangerous, as the malware leverages self-replication techniques to spread as widely as possible.