600+ Malicious npm Packages Expose Deep Supply Chain Attack in Shai-Hulud Campaign

Listen to this Post

Featured Image

Introduction

A large-scale software supply chain attack has once again shaken the JavaScript ecosystem, with more than 600 malicious packages uploaded to the npm registry in a coordinated Shai-Hulud campaign. The incident highlights how modern open source dependencies have become a primary target for threat actors seeking to compromise developer environments, steal credentials, and propagate malware across CI/CD pipelines.

This latest wave is not an isolated event. It is part of a growing pattern of self-replicating supply chain attacks that leverage trusted packages, compromised maintainer accounts, and automated build systems to spread silently through global software infrastructure.

Summary of the Original Report

Threat actors launched a coordinated supply chain attack targeting the npm ecosystem, publishing over 600 malicious package versions within a short timeframe as part of the Shai-Hulud campaign. According to security researchers, 639 malicious package versions were pushed across 323 unique npm libraries in approximately one hour, demonstrating a high level of automation and operational efficiency.

The majority of affected packages belonged to the @antv ecosystem, a widely used suite for data visualization tools including charting, graph networks, flow diagrams, and mapping libraries. However, the attack was not limited to this namespace, as several widely used independent packages were also compromised.

Security firm Socket reported that the malicious payload was designed to extract sensitive information from developer machines and CI/CD pipelines. The stolen data includes credentials and secrets from platforms such as GitHub, npm, cloud services, Kubernetes clusters, Docker environments, SSH keys, and secret management tools like Vault.

The malware also actively targets automation systems including GitHub Actions, GitLab CI, Jenkins, Azure DevOps, CircleCI, Vercel, and Netlify. Once executed, it collects sensitive data, compresses and encrypts it using multiple layers including Gzip, AES-256-GCM, and RSA-OAEP, making detection significantly harder.

In some cases, attackers used the Session peer-to-peer network for exfiltration, reducing reliance on traditional command-and-control infrastructure. When GitHub tokens were available, the malware created repositories inside victim accounts and uploaded stolen data directly, turning legitimate developer infrastructure into a data dump system.

Researchers from Endor Labs highlighted that several compromised packages, including timeago.js, size-sensor, and jest-canvas-mock, had not been updated for years. Some of these still receive millions of weekly downloads but lack modern security protections such as OIDC trusted publishing.

The Shai-Hulud campaign itself has been active since September and has expanded across multiple ecosystems, including npm, PyPI, and Composer. It is characterized by token theft, package republishing, and automated lateral movement across software supply chains.

Socket researchers have tracked more than 1,000 artifacts linked to Shai-Hulud campaigns, while other reports suggest that over 2,700 malicious GitHub repositories have been created using stolen credentials.

A newer variant of the malware introduces additional stealth mechanisms, including the ability to generate valid Sigstore provenance attestations by abusing compromised CI/CD OIDC tokens. This allows malicious packages to appear legitimate even when verified by modern supply chain security tools.

The attack is also self-propagating. Once a system is compromised, the malware enumerates npm tokens, extracts package ownership data, downloads source tarballs, injects malicious code, and republishes infected versions with incremented version numbers.

Attribution remains difficult due to overlapping tooling and leaked malware code previously exposed by other threat groups. Researchers note that while the latest variant differs technically from earlier samples, it retains the same operational structure and goals.

Experts recommend that any developers who installed affected packages should immediately remove them and rotate all credentials accessible from potentially compromised systems.

What Undercode Say:

The Shai-Hulud npm campaign represents a shift in how supply chain attacks are executed at scale. Rather than relying on single-package compromises or isolated breaches, attackers are now automating the full lifecycle of dependency poisoning, from token theft to republishing and propagation.

One of the most concerning aspects is the speed of deployment. Publishing more than 600 malicious package versions in about an hour suggests a fully automated pipeline rather than manual intrusion. This indicates that attackers are using prebuilt orchestration systems capable of scanning, injecting, and pushing code into registries with minimal human involvement.

The targeting of the @antv ecosystem is strategically significant. These packages are widely used in data visualization workflows, meaning they are often integrated into dashboards, analytics tools, and enterprise applications. A compromise at this layer gives attackers indirect access to business intelligence systems and potentially sensitive operational data.

The inclusion of dormant packages such as jest-canvas-mock and timeago.js highlights another key tactic: targeting low-maintenance but high-download libraries. These packages often lack recent security updates and are less likely to enforce modern publishing safeguards such as OIDC-based authentication.

The malware’s exfiltration strategy is particularly advanced. By combining encrypted payload storage, peer-to-peer communication via Session, and fallback GitHub repository creation, attackers significantly reduce the chances of detection and takedown. Even if one channel is blocked, others remain active.

The self-propagation mechanism turns the attack into a worm-like system inside the npm ecosystem. Once credentials are stolen, the malware can independently republish infected versions, effectively turning compromised developers into unwitting distributors of malicious code.

Another major escalation is the abuse of Sigstore and OIDC-based trust systems. By generating valid provenance attestations using stolen CI/CD tokens, attackers can bypass verification pipelines that organizations increasingly rely on for supply chain security. This undermines one of the newest defensive layers in modern DevSecOps.

The scale of GitHub repository abuse is also alarming. With thousands of rogue repositories created automatically, GitHub becomes both a storage platform and a distribution network for stolen data. This blurs the line between legitimate developer activity and malicious infrastructure abuse.

From a defensive standpoint, the most critical weakness exploited here is trust. The entire npm ecosystem depends on the assumption that published packages are safe, especially when coming from known maintainers. Once those credentials are compromised, traditional perimeter defenses become ineffective.

This campaign also demonstrates how CI/CD pipelines have become a primary attack surface. Developers often overlook the fact that build systems hold persistent secrets with broad access to production environments, cloud infrastructure, and deployment pipelines.

The use of multi-layer encryption and compression is not just obfuscation, it is designed specifically to defeat automated inspection tools. Static analysis alone is insufficient to detect such payloads, meaning behavioral monitoring inside build environments becomes essential.

Ultimately, Shai-Hulud reflects the evolution of supply chain attacks into fully autonomous ecosystems. Instead of isolated malware, we are seeing self-replicating software that behaves more like an adaptive organism within developer infrastructure.

Fact Checker Results

✅ The npm registry has previously been targeted by large-scale malicious package campaigns
⚠️ Exact numbers of affected repositories may vary depending on detection source and timeframe
⚠️ Shai-Hulud attribution remains uncertain and is still under active investigation

Prediction

The next phase of supply chain attacks will likely focus on deeper CI/CD integration abuse, especially targeting OIDC identity tokens and automated deployment pipelines.

Attackers are expected to expand self-propagation mechanisms beyond npm into container registries such as Docker Hub and cloud artifact stores.

We may also see more hybrid malware that combines credential theft with runtime exploitation inside build environments, allowing attackers not only to steal secrets but also to inject malicious code into production deployments in real time.

🕵️‍📝Let’s dive deep and fact‑check.

References:

Reported By: www.bleepingcomputer.com
Extra Source Hub (Possible Sources for article):
https://www.digitaltrends.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon