The Shai-Hulud 2.0 npm Supply Chain Attack

Updated 5 Oct 2026 · Incident date 24 Nov 2025 · npm

Package@asyncapi/cli, posthog-node, zapier-platform-core and ~796 other npm packages (poisoned versions, Nov 2025)
Filesetup_bun.js and bun_environment.js

On 24 November 2025, a second wave of the Shai-Hulud worm backdoored 796 unique npm packages across 1,092 versions. The packages included @asyncapi/cli, posthog-node and zapier-platform-core.

Datadog reports that the worm stole credentials, copied them to public GitHub repositories and published itself into more packages. Its payload ran at install time, before any of your code.

What happened

A worm took over maintainer accounts and pushed poisoned versions of their packages. Datadog traces the first victim to the asyncapi/cli GitHub repository, where weak CI/CD steps likely let malicious pull requests in. PostHog confirmed that an npm token was stolen through malicious commits.

Each poisoned package got two new files, setup_bun.js and bun_environment.js, and a preinstall script in package.json. Unit 42 notes that the first wave ran after install. This wave ran before install, so it reached developer machines and CI runners more often.

The payload:

  1. Installed the Bun runtime, so Node.js monitoring did not see the work.
  2. Searched the disk and cloud settings for secrets, with TruffleHog, .npmrc and AWS, Azure and Google Cloud secret stores.
  3. Uploaded the secrets to new public GitHub repositories described as "Sha1-Hulud: The Second Coming."
  4. Registered the machine as a self-hosted GitHub Actions runner that ran a vulnerable workflow for remote commands.
  5. Used stolen npm credentials to backdoor up to 100 more packages.
  6. Tried to destroy the home directory if it was unable to steal or spread.

Datadog counts more than 500 GitHub users with stolen credentials and more than 150 organizations hit.

Vigilance compares the version you trust with the new one. These releases gained an install script and new files that a trusted version did not have. Vigilance reports the file that gained this capability. See the scan block below.

Affected versions

Datadog counts 796 unique packages and 1,092 versions, with more than 20 million weekly downloads in total. The three names in the record are examples only. Unit 42 and Microsoft also name Zapier, PostHog, Postman, ENS Domains and AsyncAPI projects.

The sources do not give one short list of versions. Use the lists below to check your own tree.

Indicators of compromise

How to check

Search installed packages for the two payload files, and search your GitHub account for the repository description.

find . -path "*/node_modules/*" \( -name setup_bun.js -o -name bun_environment.js \) -print
gh search repos "Sha1-Hulud: The Second Coming" --owner YOUR_ORG_OR_USER

Replace the owner with your account name. Also check ~/.cache and CI caches, and list self-hosted runners in each GitHub organization.

What to do now

  1. Rotate npm tokens, GitHub personal access tokens, SSH keys and cloud credentials that any affected machine can read.
  2. Review cloud secret-store access logs, such as Key Vault, for the time of any install.
  3. Delete unknown repositories that match the description, and delete unknown workflows and self-hosted runners.
  4. Isolate CI agents that installed a bad version. Rebuild them.
  5. Use WebAuthn for npm two-factor sign-in. Microsoft also advises npm trusted publishing instead of long-lived tokens.
  6. Pin dependencies to a trusted version and review any new install script before you update.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old @asyncapi/cli-prev --new @asyncapi/cli-current
files scanned: 36 (2 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   setup_bun.js
           It runs a command on its own when it is installed, downloads from the internet and reads saved passwords and access keys.

Frequently asked questions

Which npm packages were affected by Shai-Hulud 2.0?

Datadog counts 796 unique packages and 1,092 versions. Examples are @asyncapi/cli, posthog-node and zapier-platform-core.

How does Shai-Hulud 2.0 steal credentials?

A preinstall script runs setup_bun.js and bun_environment.js. They search for secrets with TruffleHog and cloud APIs, then upload them to public GitHub repositories.

Sources

  1. securitylabs.datadoghq.com/articles/shai-hulud-2.0-npm-worm/
  2. unit42.paloaltonetworks.com/npm-supply-chain-attack/
  3. microsoft.com/en-us/security/blog/2025/12/09/shai-hulud-2-0-guidance-for-detecting-investigating-and-defending-against-the-supply-chain-attack/

More supply chain attacks

All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free