The New Supply Chain Threat: How Modern Malware Turns Open Source Into an Attack Surface

Four hard drives cut into pieces are arranged neatly on a green surface, showcasing their internal circuits and metal platters—a reminder of the importance of Security by Design and Embedded Protection in safeguarding sensitive data.

Evolved variation of the malicious Shai-Hulud is posing an increasing risk to SMEs in London, Manchester and across the UK

Summary: What Leaders Need To Know Right Now

Shai-Hulud v2, a rapidly spreading supply chain attack, has compromised hundreds of NPM packages and even surfaced in the Java ecosystem. The campaign uses stolen maintainer credentials to turn trusted open source libraries into delivery systems for credential theft and potentially destructive payloads.

For creative agencies, SaaS companies, product engineering teams (and indeed, any organisation that builds on open source). This represents a major shift; The tools your developers rely on are becoming vectors for silent compromise.

The perimeter is no longer your network. It is every package your systems download.

  • Read this if: you need a clear overview as to how Shai-Hulud operates, and how to protect from such open source package infections
  • Key takeaway: Supply chain security must now be treated as a core business function. Open source trust can no longer be implicit.

A New, Large-Scale Attack (and a particularly nasty dead-man’s switch)

In 2025, open-source supply chains have become a frontline of cyber-risk, and not just for developers. A new, evolved variant of the Shai-Hulud worm is quietly spreading across hundreds of NPM (and even some Maven) packages. The result: trusted dependencies now represent one of the most potent attack surfaces.

Far from being a one-off blip, this is a systemic shift: malicious actors are no longer targeting single apps or companies. They are weaponising the very tools we all rely on. If you build on open-source or use third-party packages, assume you are exposed and move supply-chain security from “nice to have” to a board-level priority.

The Attack Vector and Scope

The Socket Research Team and GitLab Vulnerability Research (among others) have confirmed that a second wave of the Shai-Hulud campaign, dubbed “v2” or “The Second Coming” is now live. According to Socket, this wave has already compromised 500+ NPM packages and 700+ versions.

The worm isn’t limited to JavaScript: there’s documented spill-over into the Java/Maven ecosystem. Infected packages include malicious preinstall / install-lifecycle scripts (notably setup_bun.js, which loads a hidden payload bun_environment.js.) Once executed, this worm harvests credentials like NPM tokens, GitHub credentials and cloud keys, then attempts to propagate itself by publishing new malicious versions under the victim’s identity.

Arguably the most malicious part? It is speculated that some instances are incorporating a “dead man’s switch” if the malware’s infrastructure becomes unreachable – e.g., if exfiltration or propagation fails – that could trigger a wipe of local data and/or home directories.

This turns a supply chain compromise into a potential business continuity threat.

Why This Matters: The Supply-Chain Has Become the New Perimeter

1. From Code Packages to a Digital Trojan Horse

Open-source packages, once assumed safe by virtue of being widely used, are now being weaponised. Installing a dependency can silently introduce backdoors, credential theft, and a worm that spreads across your entire organisation.

2. Mass Reach, Mass Exposure

Many of the affected packages belong to well-known projects used by thousands of companies including organisations dependent on frameworks or libraries from vendors like Zapier, PostHog, ENS Domains, Postman, AsyncAPI and more.

Because the worm spreads automatically – re-publishing itself under compromised maintainers – the blast radius grows rapidly. In some reports, tens of thousands of repositories have been seeded with stolen credentials; cross-victim exfiltration is a confirmed pattern.

3. Trust Has Become a Liability

In past decades, your codebase and your own infrastructure were your main risk boundaries. Now, your dependencies are effectively third-party code you run inside your own environment.

Trusting them “because they’re popular” is no longer a safe assumption. Ultimately, well known maintainers have built reputations that allow their updates to be accepted automatically. Attackers understand this; they do not need to exploit vulnerabilities in your code, they only need your systems to install code you already trust.

This creates a new hierarchy of risk:

  1. Your dependencies
  2. The maintainers of those dependencies
  3. The security of the ecosystem that distributes them

Dr Logic’s Strategic Recommendations

1. Build cognitive awareness across technical teams

Educate engineers, DevOps teams, and technical leaders that supply chain attacks are not theoretical. They are active, widespread, and financially motivated. Awareness reduces accidental propagation and encourages healthier security habits.

2. Reduce the exposed surface area of your open source use

Review how many packages you pull, how often you update them, and how deeply you trust them. Remove unnecessary dependencies. Pin versions intentionally rather than automatically. Limit the execution of install scripts wherever possible.

3. Reinforce authentication hygiene across your organisation

Rotate tokens and credentials that may have been exposed. Replace long lived tokens with scoped, short lived ones. Ensure developers avoid storing secrets on local machines. Move toward centralised secret management.

4. Validate critical actions with independent verification

Require manual review for any package publishing, changes to CI pipelines, or unusual automated workflows. This helps catch malicious republishing attempts that use stolen credentials.

5. Strengthen your build pipeline

Block lifecycle scripts in CI environments unless explicitly approved. Introduce dependency scanning and integrity checks. Generate software bills of materials so you can identify vulnerable components quickly.

6. Prepare for destructive contingencies

Because some variants include destructive logic, your response plan should cover not only credential rotation but also restoration strategies for developer workstations and build servers.


The New Reality

The return of Shai-Hulud is not an isolated incident. It represents a structural change in how attackers think. They want reach, leverage, and scale. Compromising the software supply chain gives them all three.

Security is no longer only about protecting your network. It is about understanding the trust you place in every external component your systems rely on.

Managing this is no longer optional. It is a core part of modern risk management for any organisation that builds software, regardless of size or industry.

Ready to Discuss Getting Proactive on Malware, Not Reactive?

Dr Logic provides integrated IT SupportCyber Security, and IT Strategy & Innovation, designed around the needs of creative agencies, financial services, and fast-growth businesses with an Apple-to-the-core philosophy.

Let us help you build a security posture that is not just compliant, but genuinely resilient.

Discover how Dr Logic makes technology feel effortless and safe through mastery, secure architecture, and real relationships that show up when it matters.

Contact Dr Logic Today to Schedule a Strategic IT Review.

DR Logic

Dr Logic is an Apple Premium Technical Partner supporting businesses across London and the UK. Founded in 2003, the team of 34 Apple-certified engineers and consultants helps organisations get the most from their technology through proactive IT support, cyber security, and strategic IT planning.

Explore More Articles

Clear, Actionable Advice – No Jargon, No Pressure.

Get In Touch With an IT Expert

Scaling up, tackling downtime, or reviewing your setup? Contact us or book a quick call for expert advice on running your IT smarter and more securely.

Rather speak to us right now? Our phone number is: 020 3642 6540


Contact Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Book a Consultation Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Want IT to Work Smarter for You?

Get expert tips, security advice, and practical insights for Apple and hybrid teams – straight to your inbox.


Subscription Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.