The Shai-Hulud 2.0 npm Supply Chain Attack
Updated 5 Oct 2026 · Incident date 24 Nov 2025 · npm
@asyncapi/cli, posthog-node, zapier-platform-core and ~796 other npm packages (poisoned versions, Nov 2025)setup_bun.js and bun_environment.jsOn 24 November 2025, a second wave of the Shai-Hulud worm backdoored 796 unique npm packages across 1,092 versions. The packages included @asyncapi/cli, posthog-node and zapier-platform-core.
Datadog reports that the worm stole credentials, copied them to public GitHub repositories and published itself into more packages. Its payload ran at install time, before any of your code.
What happened
A worm took over maintainer accounts and pushed poisoned versions of their packages. Datadog traces the first victim to the asyncapi/cli GitHub repository, where weak CI/CD steps likely let malicious pull requests in. PostHog confirmed that an npm token was stolen through malicious commits.
Each poisoned package got two new files, setup_bun.js and bun_environment.js, and a preinstall script in package.json. Unit 42 notes that the first wave ran after install. This wave ran before install, so it reached developer machines and CI runners more often.
The payload:
- Installed the Bun runtime, so Node.js monitoring did not see the work.
- Searched the disk and cloud settings for secrets, with TruffleHog,
.npmrcand AWS, Azure and Google Cloud secret stores. - Uploaded the secrets to new public GitHub repositories described as "Sha1-Hulud: The Second Coming."
- Registered the machine as a self-hosted GitHub Actions runner that ran a vulnerable workflow for remote commands.
- Used stolen npm credentials to backdoor up to 100 more packages.
- Tried to destroy the home directory if it was unable to steal or spread.
Datadog counts more than 500 GitHub users with stolen credentials and more than 150 organizations hit.
Vigilance compares the version you trust with the new one. These releases gained an install script and new files that a trusted version did not have. Vigilance reports the file that gained this capability. See the scan block below.
Affected versions
Datadog counts 796 unique packages and 1,092 versions, with more than 20 million weekly downloads in total. The three names in the record are examples only. Unit 42 and Microsoft also name Zapier, PostHog, Postman, ENS Domains and AsyncAPI projects.
The sources do not give one short list of versions. Use the lists below to check your own tree.
- Datadog and Microsoft link to the full set of affected packages in their reports.
- Your own tool can compare
package-lock.jsonagainst a feed of known malicious versions.
Indicators of compromise
- Files in a package:
setup_bun.jsandbun_environment.js, with apreinstallscript inpackage.json. - GitHub repository description: "Sha1-Hulud: The Second Coming." Repository names use 18 random lowercase letters and digits.
- GitHub workflow named "Discussion Create" (
discussion.yaml) and a runner agent namedSHA1HULUD. - SHA-256 of
setup_bun.js:a3894003ad1d293ba96d77881ccd2071446dc3f65f434669b49b3da92421901a. - Other hashes (Unit 42):
62ee164b9b306250c1172583f138c9614139264f889fa99614903c12755468d0,f099c5d9ec417d4445a0328ac0ada9cde79fc37410914103ae9c609cbc0ee068,cbb9bc5a8496243e02f3cc080efbe3e4a1430ba0671f2e43a202bf45b05479cd. - Webhook (Unit 42):
webhook[.]site/bb8ca5f6-4175-45d2-b042-fc9ebb8170b7. - Microsoft Defender alert names: "Sha1-Hulud Campaign Detected" and Trojan:JS/ShaiWorm.
How to check
Search installed packages for the two payload files, and search your GitHub account for the repository description.
find . -path "*/node_modules/*" \( -name setup_bun.js -o -name bun_environment.js \) -print
gh search repos "Sha1-Hulud: The Second Coming" --owner YOUR_ORG_OR_USER
Replace the owner with your account name. Also check ~/.cache and CI caches, and list self-hosted runners in each GitHub organization.
What to do now
- Rotate npm tokens, GitHub personal access tokens, SSH keys and cloud credentials that any affected machine can read.
- Review cloud secret-store access logs, such as Key Vault, for the time of any install.
- Delete unknown repositories that match the description, and delete unknown workflows and self-hosted runners.
- Isolate CI agents that installed a bad version. Rebuild them.
- Use WebAuthn for npm two-factor sign-in. Microsoft also advises npm trusted publishing instead of long-lived tokens.
- Pin dependencies to a trusted version and review any new install script before you update.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 36 (2 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE setup_bun.js It runs a command on its own when it is installed, downloads from the internet and reads saved passwords and access keys.
Frequently asked questions
Which npm packages were affected by Shai-Hulud 2.0?
Datadog counts 796 unique packages and 1,092 versions. Examples are @asyncapi/cli, posthog-node and zapier-platform-core.
How does Shai-Hulud 2.0 steal credentials?
A preinstall script runs setup_bun.js and bun_environment.js. They search for secrets with TruffleHog and cloud APIs, then upload them to public GitHub repositories.
Sources
More supply chain attacks
- @apexacc/cli Defender-blinding C2 loader 17 Sept 2026
- keyv / cacheable npm worm (Shai-Hulud third wave) 4 Aug 2026
- Mastra AI npm compromise (Sapphire Sleet) 17 Jun 2026
- TanStack npm compromise (Mini Shai-Hulud) 11 May 2026
All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.