Evolved variation of the malicious Shai-Hulud is posing an increasing risk to SMEs in London, Manchester and across the UK
Summary: What Leaders Need To Know Right Now
Shai-Hulud v2, a rapidly spreading supply chain attack, has compromised hundreds of NPM packages and even surfaced in the Java ecosystem. The campaign uses stolen maintainer credentials to turn trusted open source libraries into delivery systems for credential theft and potentially destructive payloads.
For creative agencies, SaaS companies, product engineering teams (and indeed, any organisation that builds on open source). This represents a major shift; The tools your developers rely on are becoming vectors for silent compromise.
The perimeter is no longer your network. It is every package your systems download.
- Read this if: you need a clear overview as to how Shai-Hulud operates, and how to protect from such open source package infections
- Key takeaway: Supply chain security must now be treated as a core business function. Open source trust can no longer be implicit.
A New, Large-Scale Attack (and a particularly nasty dead-man’s switch)
In 2025, open-source supply chains have become a frontline of cyber-risk, and not just for developers. A new, evolved variant of the Shai-Hulud worm is quietly spreading across hundreds of NPM (and even some Maven) packages. The result: trusted dependencies now represent one of the most potent attack surfaces.
Far from being a one-off blip, this is a systemic shift: malicious actors are no longer targeting single apps or companies. They are weaponising the very tools we all rely on. If you build on open-source or use third-party packages, assume you are exposed and move supply-chain security from “nice to have” to a board-level priority.
The Attack Vector and Scope
The Socket Research Team and GitLab Vulnerability Research (among others) have confirmed that a second wave of the Shai-Hulud campaign, dubbed “v2” or “The Second Coming” is now live. According to Socket, this wave has already compromised 500+ NPM packages and 700+ versions.
The worm isn’t limited to JavaScript: there’s documented spill-over into the Java/Maven ecosystem. Infected packages include malicious preinstall / install-lifecycle scripts (notably setup_bun.js, which loads a hidden payload bun_environment.js.) Once executed, this worm harvests credentials like NPM tokens, GitHub credentials and cloud keys, then attempts to propagate itself by publishing new malicious versions under the victim’s identity.
Arguably the most malicious part? It is speculated that some instances are incorporating a “dead man’s switch” if the malware’s infrastructure becomes unreachable – e.g., if exfiltration or propagation fails – that could trigger a wipe of local data and/or home directories.
This turns a supply chain compromise into a potential business continuity threat.
Why This Matters: The Supply-Chain Has Become the New Perimeter
1. From Code Packages to a Digital Trojan Horse
Open-source packages, once assumed safe by virtue of being widely used, are now being weaponised. Installing a dependency can silently introduce backdoors, credential theft, and a worm that spreads across your entire organisation.
2. Mass Reach, Mass Exposure
Many of the affected packages belong to well-known projects used by thousands of companies including organisations dependent on frameworks or libraries from vendors like Zapier, PostHog, ENS Domains, Postman, AsyncAPI and more.
Because the worm spreads automatically – re-publishing itself under compromised maintainers – the blast radius grows rapidly. In some reports, tens of thousands of repositories have been seeded with stolen credentials; cross-victim exfiltration is a confirmed pattern.
3. Trust Has Become a Liability
In past decades, your codebase and your own infrastructure were your main risk boundaries. Now, your dependencies are effectively third-party code you run inside your own environment.
Trusting them “because they’re popular” is no longer a safe assumption. Ultimately, well known maintainers have built reputations that allow their updates to be accepted automatically. Attackers understand this; they do not need to exploit vulnerabilities in your code, they only need your systems to install code you already trust.
This creates a new hierarchy of risk:
- Your dependencies
- The maintainers of those dependencies
- The security of the ecosystem that distributes them
Dr Logic’s Strategic Recommendations
1. Build cognitive awareness across technical teams
Educate engineers, DevOps teams, and technical leaders that supply chain attacks are not theoretical. They are active, widespread, and financially motivated. Awareness reduces accidental propagation and encourages healthier security habits.
2. Reduce the exposed surface area of your open source use
Review how many packages you pull, how often you update them, and how deeply you trust them. Remove unnecessary dependencies. Pin versions intentionally rather than automatically. Limit the execution of install scripts wherever possible.
3. Reinforce authentication hygiene across your organisation
Rotate tokens and credentials that may have been exposed. Replace long lived tokens with scoped, short lived ones. Ensure developers avoid storing secrets on local machines. Move toward centralised secret management.
4. Validate critical actions with independent verification
Require manual review for any package publishing, changes to CI pipelines, or unusual automated workflows. This helps catch malicious republishing attempts that use stolen credentials.
5. Strengthen your build pipeline
Block lifecycle scripts in CI environments unless explicitly approved. Introduce dependency scanning and integrity checks. Generate software bills of materials so you can identify vulnerable components quickly.
6. Prepare for destructive contingencies
Because some variants include destructive logic, your response plan should cover not only credential rotation but also restoration strategies for developer workstations and build servers.
The New Reality
The return of Shai-Hulud is not an isolated incident. It represents a structural change in how attackers think. They want reach, leverage, and scale. Compromising the software supply chain gives them all three.
Security is no longer only about protecting your network. It is about understanding the trust you place in every external component your systems rely on.
Managing this is no longer optional. It is a core part of modern risk management for any organisation that builds software, regardless of size or industry.
Ready to Discuss Getting Proactive on Malware, Not Reactive?
Dr Logic provides integrated IT Support, Cyber Security, and IT Strategy & Innovation, designed around the needs of creative agencies, financial services, and fast-growth businesses with an Apple-to-the-core philosophy.
Let us help you build a security posture that is not just compliant, but genuinely resilient.
Discover how Dr Logic makes technology feel effortless and safe through mastery, secure architecture, and real relationships that show up when it matters.



















































