On November 21-24, 2025, a massive second wave of the Sha1-Hulud supply chain attack compromised over 600 npm packages belonging to major organizations, including Zapier, ENS Domains, PostHog, AsyncAPI, and Postman. The attack affected over 25,000 repositories, with an average of approximately 1,000 new repositories compromised every 30 minutes at the height of the activity. These packages account for a total of 132 million monthly downloads, creating extremely broad exposure within the JavaScript ecosystem.
| Date | 2025-11-26 17:26:49 |
Technical Summary
The attack represents a significant evolution from the Shai-Hulud campaign of September 2025, introducing several dangerous new capabilities. The attackers compromised maintainer accounts to publish trojanized versions that execute during the preinstall phase, ensuring execution on build servers and bypassing static scanning tools.
The malicious payload uses a two-stage approach:
- During the preinstall phase,
setup_bun.jsinstalls or locates the Bun runtime bun_environment.jsthen executes the main malicious payload
Key malicious capabilities:
- Automated credential theft using TruffleHog to scan for npm tokens, cloud credentials, and environment variables
- Automated registration of self-hosted GitHub runners with malicious workflows for command execution
- Cross-victim exfiltration, where one victim’s secrets are sent to another victim’s repository
- Self-regeneration mechanism via GitHub search to recover if repositories are deleted
- Automated propagation that infects up to 100 packages for every compromised token
Destructive deletion functionalitythat wipes the user’s entire home directory if exfiltration fails- Privilege escalation on Linux via Docker to obtain root access
Compromised packages and their versions: The following packages (492 in total) have been confirmed as compromised in this wave. Key affected packages include:
| Organization | Key compromised packages |
|---|---|
| AsyncAPI | @asyncapi/cli, @asyncapi/generator, @asyncapi/parser |
| PostHog | posthog-node, posthog-js, @posthog/cli |
| Postman | @postman/secret-scanner-wasm, @postman/csv-parse |
| ENS Domains | @ensdomains/ensjs, @ensdomains/ui, @ensdomains/thorin |
| Zapier | @zapier/zapier-sdk, zapier-platform-core, zapier-platform-cli |
[The full list of 492 packages]
@asyncapi/diff
@asyncapi/nodejs-ws-template
go-template
… (full list omitted for brevity)
Recommendations
Immediate containment: Scan all projects for the packages listed above and immediately remove the compromised versions. Clean npm/yarn/pnpm caches and re-examine package-lock files.
Credential rotation: Assume all credentials are compromised. Immediately rotate:
- NPM tokens (especially before the deprecation of classic npm tokens scheduled for December 9)
- Cloud provider credentials (AWS, GCP, Azure)
- GitHub personal access tokens and OAuth tokens
- Any other secrets stored in development environments
- Repository audit: Check all GitHub repositories for:
- Unexpected public repositories with random 18-character names
- Suspicious workflow files in .github/workflows/
- Unexpected self-hosted runners named “SHA1HULUD”
- Repository descriptions containing “Sha1-Hulud: The Second Coming”
- Supply chain hardening:
- Enforce strict dependency pinning and the use of lock files
- Implement automated dependency scanning with notifications
- Migrate to npm trusted publishing before the December 9 deadline
- Enable 2FA with hardware keys for all maintainer accounts
- Incident response: Assume the compromise of any system that has executed these packages. Conduct a full forensic analysis of build systems and potentially exposed developer workstations.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
