Supply Chain Incident
Shai-Hulud 2.0 npm supply-chain worm wave
A second Shai-Hulud wave compromised hundreds of npm packages through install-time malware, GitHub token theft, and public repositories containing exfiltrated secrets.
Affected Packages
No structured records.
Affected Releases
No structured records.
Repositories
No structured records.
Organizations
No structured records.
Maintainers
No structured records.
Threat Actors
Campaigns
Build Systems
- GitHub Actions
Distribution Channels
- GitHub repositories
- npm registry
Compromised Accounts
- compromised npm maintainer tokens
- victim GitHub tokens
Connected Entities
- compromised npm maintainer tokensCompromised Account
- GitHub ActionsBuild System
- GitHub repositoriesDistribution Channel
- npm registryDistribution Channel
- TeamPCPThreat Actor
- TeamPCP Multi-Ecosystem Supply Chain CampaignCampaign
- victim GitHub tokensCompromised Account
Attribution Evidence
Microsoft and Wiz describe the second Shai-Hulud wave as part of the same coherent supply-chain worm activity tracked in the broader TeamPCP/Shai-Hulud cluster.
The campaign edge keeps the second Shai-Hulud wave attached to the 2026 multi-ecosystem supply-chain activity rather than creating a standalone actor.
References
- Shai-Hulud 2.0: Guidance for detecting, investigating, and defending against the supply chain attackMicrosoft Security Blog · 2025-12-09
- Shai-Hulud 2.0 Supply Chain Attack: 25K+ Repos ExposedWiz · 2025-12-09
- New npm Supply Chain Attack Identified: Second Wave of Shai HuludeSentire · 2025-11-24