Supply Chain Incident
Shai-Hulud npm self-propagating package compromise
The Shai-Hulud campaign compromised npm packages with credential-harvesting malware that used stolen npm tokens to publish malicious versions of additional packages.
Evidence-Gated Propagation
Propagation Timeline
- Release@ctrl/tinycolor@4.1.1
pkg:npm/%40ctrl/tinycolor@4.1.1TemporalRelease@ctrl/tinycolor@4.1.2pkg:npm/%40ctrl/tinycolor@4.1.2The npm registry metadata records adjacent malicious @ctrl/tinycolor releases on the same date; this edge preserves ordered wave structure without asserting causation.
- Packagerxnt-authenticationTemporalRelease@ctrl/tinycolor@4.1.1
pkg:npm/%40ctrl/tinycolor@4.1.1Public reporting places rxnt-authentication activity before the @ctrl/tinycolor wave and describes token reuse, but this edge is temporal precedence rather than asserted package-to-package causation.
Affected Packages
Affected Releases
- @ctrl/tinycolor@4.1.1pkg:npm/%40ctrl/tinycolor@4.1.1 · published 2025-09-15Release
- @ctrl/tinycolor@4.1.2pkg:npm/%40ctrl/tinycolor@4.1.2 · published 2025-09-15Release
Repositories
No structured records.
Organizations
Maintainers
No structured records.
Threat Actors
- Shai-Hulud operator
Campaigns
No structured records.
Build Systems
- GitHub Actions
Distribution Channels
- GitHub Actions workflow
- npm registry
Compromised Accounts
- compromised npm maintainer tokens
- victim GitHub tokens
Connected Entities
- @ctrl/tinycolorPackage
- @ctrl/tinycolor@4.1.1Release
- @ctrl/tinycolor@4.1.2Release
- compromised npm maintainer tokensCompromised Account
- ctrlOrganization
- GitHub ActionsBuild System
- GitHub Actions workflowDistribution Channel
- npm registryDistribution Channel
- rxntOrganization
- rxnt-authenticationPackage
- Shai-Hulud operatorThreat Actor
- victim GitHub tokensCompromised Account
Attribution Evidence
Public reporting supports a coherent Shai-Hulud operator/campaign behavior, but this corpus does not assign a named APT or state sponsor.
References
- Shai-Hulud: Self-Replicating Worm Compromises 500+ NPM PackagesStepSecurity · 2025-09-15
- Shai-Hulud: Ongoing Package Supply Chain Worm Delivering Data-Stealing MalwareWiz · 2025-09-16
- @ctrl/tinycolor npm registry metadatanpm · 2025-09-15