NPM Supply Chain Attack: Second Wave of Sha1-Hulud Compromises Over 25,000 Repositories

ISGroup Cybersecurity

On November 21-24, 2025, a massive second wave of the Sha1-Hulud supply chain attack compromised over 600 npm packages belonging to major organizations, including Zapier, ENS Domains, PostHog, AsyncAPI, and Postman. The attack affected over 25,000 repositories, with an average of approximately 1,000 new repositories compromised every 30 minutes at the height of the activity. These packages account for a total of 132 million monthly downloads, creating extremely broad exposure within the JavaScript ecosystem.

Date2025-11-26 17:26:49

Technical Summary

The attack represents a significant evolution from the Shai-Hulud campaign of September 2025, introducing several dangerous new capabilities. The attackers compromised maintainer accounts to publish trojanized versions that execute during the preinstall phase, ensuring execution on build servers and bypassing static scanning tools.

The malicious payload uses a two-stage approach:

  • During the preinstall phase, setup_bun.js installs or locates the Bun runtime
  • bun_environment.js then executes the main malicious payload

Key malicious capabilities:

  • Automated credential theft using TruffleHog to scan for npm tokens, cloud credentials, and environment variables
  • Automated registration of self-hosted GitHub runners with malicious workflows for command execution
  • Cross-victim exfiltration, where one victim’s secrets are sent to another victim’s repository
  • Self-regeneration mechanism via GitHub search to recover if repositories are deleted
  • Automated propagation that infects up to 100 packages for every compromised token
  • Destructive deletion functionality that wipes the user’s entire home directory if exfiltration fails
  • Privilege escalation on Linux via Docker to obtain root access

Compromised packages and their versions: The following packages (492 in total) have been confirmed as compromised in this wave. Key affected packages include:

Organization Key compromised packages
AsyncAPI @asyncapi/cli, @asyncapi/generator, @asyncapi/parser
PostHog posthog-node, posthog-js, @posthog/cli
Postman @postman/secret-scanner-wasm, @postman/csv-parse
ENS Domains @ensdomains/ensjs, @ensdomains/ui, @ensdomains/thorin
Zapier @zapier/zapier-sdk, zapier-platform-core, zapier-platform-cli

[The full list of 492 packages]

@asyncapi/diff
@asyncapi/nodejs-ws-template
go-template
… (full list omitted for brevity)

Recommendations

  1. Immediate containment: Scan all projects for the packages listed above and immediately remove the compromised versions. Clean npm/yarn/pnpm caches and re-examine package-lock files.

  2. Credential rotation: Assume all credentials are compromised. Immediately rotate:

  • NPM tokens (especially before the deprecation of classic npm tokens scheduled for December 9)
  • Cloud provider credentials (AWS, GCP, Azure)
  • GitHub personal access tokens and OAuth tokens
  • Any other secrets stored in development environments
  1. Repository audit: Check all GitHub repositories for:
  • Unexpected public repositories with random 18-character names
  • Suspicious workflow files in .github/workflows/
  • Unexpected self-hosted runners named “SHA1HULUD”
  • Repository descriptions containing “Sha1-Hulud: The Second Coming”
  1. Supply chain hardening:
  • Enforce strict dependency pinning and the use of lock files
  • Implement automated dependency scanning with notifications
  • Migrate to npm trusted publishing before the December 9 deadline
  • Enable 2FA with hardware keys for all maintainer accounts
  1. Incident response: Assume the compromise of any system that has executed these packages. Conduct a full forensic analysis of build systems and potentially exposed developer workstations.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert