🦞🌯 Lobster Roll

Thread

Shai Hulud launches second supply-chain attack (aikido.dev)

Stories related to "Shai Hulud launches second supply-chain attack" across the full archive.

Shai Hulud launches second supply-chain attack (aikido.dev)
Shai-Hulud Supply-Chain Scanner (Rust) (github.com)
Self-Replicating NPM Package Supply Chain Worm 'Shai Hulud' (aikido.dev)
Shai-Hulud Strikes Again, Again. (NPM Supply Chain Attack) (socket.dev)
OreNPMGuard v2.0.0 – OSS for Shai-Hulud 2.0 NPM supply chain attack
Shai-Hulud 2.0 emerged in November 2025, compromising 738 npm packages and affecting 25,000+ repositories. This is an evolution of the September 2025 attack with new attack vectors:<p>- Uses `preinstall` hooks (executes earlier than `postinstall`) - Creates malicious GitHub workflows with self-hoste...
Shai-Hulud 2.0 Supply Chain Attack: 25K+ Repos Exposing Secrets (wiz.io)
Talos Secure Workstation launches on CrowdSupply, funding opens early October (crowdsupply.com)
Kubernetes launches second "production readiness" retrospective survey (groups.google.com)
IKEA launches secondhand marketplace to compete with eBay (ft.com)
Bluesky launches 60 second mp4, mpeg, webm and mov video clips with safety tools (bsky.social)
ULA launches second Vulcan flight, encounters strap-on booster anomaly (spaceflightnow.com)
Cerebras launches Qwen3-235B, achieving 1.5k tokens per second (cerebras.ai)
Recycling or Second Use? Supply Potential and Climate Impact of EOL EV Batteries (pubs.acs.org)
Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised (socket.dev)
A lot of blogs on this are AI generated and such as this is developing, so just linking to a bunch of resources out there:<p>Socket:<p>- Sep 15 (First post on breach): <a href="https:&#x2F;&#x2F;socket.dev&#x2F;blog&#x2F;tinycolor-supply-chain-attack-affects-40-packages" rel="nofollow">https:&#x2F;&...
Live updates: Shai-hulud, the most dangerous NPM breach in history (koi.security)
Shai-Hulud: The novel self-replicating worm infecting hundreds of NPM packages (sysdig.com)
Shai-Hulud: The novel self-replicating worm infecting NPM packages (sysdig.com)
How Replit Is Protecting You from the "Shai-Hulud" Worm (blog.replit.com)
Shai-Hulud, The Most Dangerous NPM Breach In History Affecting CrowdStrike and Hundreds of Popular Packages (koi.security)
Japan Launches Second Osmotic Power Plant in Fukuoka (oilprice.com)
Shai-Hulud Returns: Over 300 NPM Packages Infected (helixguard.ai)
https:&#x2F;&#x2F;www.aikido.dev&#x2F;blog&#x2F;shai-hulud-strikes-again-hitting-zapier-ensdomains
Shai-Hulud Returns: Over 300 NPM Packages infected via Fake Bun Runtime Within Hours (helixguard.ai)
SHA1-Hulud – The Second Coming: Over 1k NPM Packages Compromised (koi.ai)
Shai-Hulud malware infects 500 NPM packages, leaks secrets on GitHub (bleepingcomputer.com)
Shai Hulud Strikes Again (aikido.dev)
Big attack on NPM – Shai-Hulud 2.0 (about.gitlab.com)
SHA1-Hulud, NPM supply chain incident (snyk.io)
Post-mortem of Shai-Hulud attack on November 24th, 2025 (posthog.com)
The Shai-Hulud 2.0 npm worm: analysis, and what you need to know (securitylabs.datadoghq.com)
PyPI and Shai-Hulud: Staying Secure Amid Emerging Threats (blog.pypi.org)