Shai-Hulud 2.0: The Fast-Spreading npm Supply-Chain Worm, How It Works, How to Detect It
Shai-Hulud 2.0 is a fast-spreading software supply-chain worm that trojanized hundreds of npm packages in late November 2025, stealing cloud and GitHub credentials and automatically backdooring development environments. It builds on the first “Shai-Hulud” wave from September 2025 but adds far more automation, stealth and blast radius, impacting popular projects like PostHog, Postman, Zapier and ENS Domains. This article explains what the attack is, where the name came from, what is publicly known about the “author,” and provides detailed detection and remediation steps for developers and DevOps teams. A link to the public list of infected npm packages is included at the end. What Is The Shai-Hulud 2.0 Supply Chain Attack? In November 2025, security researchers disclosed “Shai-Hulud 2.0” (also called Sha1-Hulud v2), one of the most aggressive npm supply-chain attacks ever observed. Attackers hijacked maintainer accounts, injected malicious versions into npm, and used lifecycle sc...