OreNPMGuard - Shai-Hulud Package Scanner
Version 2.0.0 - Shai-Hulud 2.0 Detection & Enhanced Prevention System
A security tool to detect compromised npm packages from the Shai-Hulud supply chain attacks (original September 2025 and Shai-Hulud 2.0 November 2025). Scans both package.json and package-lock.json files to detect exact installed versions and Indicators of Compromise (IoCs). Available in both Python and Node.js implementations with centralized YAML configuration for easy maintenance.
Latest Update: November 24, 2025 - 738+ compromised packages tracked with 1,291 unique package@version combinations. Now detects both original Shai-Hulud and Shai-Hulud 2.0 attack variants.
For multi-ecosystem scanning, see ore-mal-pkg-inspector.
For multi-ecosystem malicious package scanning (npm, PyPI, Maven, RubyGems, Go, Cargo), see:
ore-mal-pkg-inspector - Comprehensive malicious package scanner with dynamic threat intelligence.
OreNPMGuard focuses specifically on Shai-Hulud attack defense for npm packages.
π¨ About the Shai-Hulud Attacks
Shai-Hulud is a self-replicating worm that began compromising npm packages on September 14-15, 2025, representing the first successful self-propagating attack in the npm ecosystem and one of the most severe JavaScript supply-chain attacks observed to date. Named after the giant sandworms from Frank Herbert's Dune series, this malware has evolved into multiple variants.
Original Shai-Hulud (September 2025)
The original attack infected 200+ npm packages (as tracked in this tool) with multiple versions affected per package.
Shai-Hulud 2.0 (November 2025) - NEW
A new variant emerged in November 2025 with significant changes:
- 738+ compromised packages with 1,291 unique package@version combinations
- 25,000+ affected repositories across ~350 unique users
- New execution phase: Uses
preinstall scripts (not just postinstall)
- New payload files:
setup_bun.js and bun_environment.js (in addition to bundle.js)
- Enhanced persistence: Creates self-hosted runners named 'SHA1HULUD' and new GitHub workflow patterns
- Multi-cloud targeting: AWS, Azure, and GCP credential harvesting
- Docker privilege escalation: Attempts to gain root access via privileged containers
- Packages uploaded between November 21-23, 2025
Reference: Wiz Research - Shai-Hulud 2.0 Blog Post
π¦ How the Attack Works
Patient Zero: The attack started with the rxnt-authentication package published on September 14, 2025, at 17:58:50 UTC by the compromised "techsupportrxnt" npm account.
Attack Chain (Original Shai-Hulud):
- Installation: Malicious package runs
postinstall script executing bundle.js (3MB+ JavaScript payload)
- Credential Harvesting: Uses TruffleHog to scan for GitHub/npm tokens, AWS/GCP/Azure credentials, environment variables, and IMDS-exposed cloud keys
- Data Exfiltration: Creates public "Shai-Hulud" repository under victim's GitHub account with stolen secrets in
data.json (double base64-encoded)
- Persistence: Injects malicious GitHub Actions workflow (
.github/workflows/shai-hulud-workflow.yml) that exfiltrates repository secrets to webhook[.]site
- Repository Migration: Forces private organizational repositories to become public personal repositories with "-migration" suffix and "Shai-Hulud Migration" description
- Worm Propagation: Uses stolen npm tokens to inject malware into other packages maintained by the victim, incrementing version numbers and adding
postinstall hooks
Attack Chain (Shai-Hulud 2.0 - November 2025):
- Installation: Malicious package runs
preinstall script executing setup_bun.js or bun_environment.js (new payload files)
- Data File Creation: Creates
cloud.json, contents.json, environment.json, and truffleSecrets.json files
- Credential Harvesting: Multi-cloud targeting (AWS, Azure, GCP) using official SDKs, scraping credentials from config files, environment variables, and IMDS
- Self-Hosted Runner Registration: Registers infected machine as self-hosted runner named 'SHA1HULUD'
- GitHub Workflow Injection:
- Creates
.github/workflows/discussion.yaml with self-hosted runner for backdoor access
- Creates
.github/workflows/formatter_*.yml for secret exfiltration (then deletes workflow to hide activity)
- Docker Privilege Escalation: Attempts to gain root access via
docker run --rm --privileged -v /:/host
- Cloud Secret Dumping: Uses authenticated sessions to dump secrets from AWS Secrets Manager, Google Secret Manager, and Azure Key Vault
- Repository Creation: Creates repositories with "Shai-Hulud" in description for exfiltration
π― What Gets Stolen
- Development Credentials: GitHub PATs (
ghp_*, gho_*), npm authentication tokens
- Cloud Credentials: AWS, GCP, Azure access keys and tokens
- API Keys: Atlassian, Datadog, and other service credentials
- System Information: Environment variables, host details, user accounts
- Source Code: Private repositories made public or cloned
π Impact Scale
Original Shai-Hulud (September 2025):
- 200+ packages compromised in this tracking database (including popular packages like
@ctrl/tinycolor, ngx-bootstrap)
- Multiple GitHub accounts compromised (exact count varies by reporting source)
- Public repositories created with "Shai-Hulud Migration" label
- Developers potentially affected through package dependencies
Shai-Hulud 2.0 (November 2025):
- 738+ compromised packages with 1,291 unique package@version combinations
- 25,000+ affected repositories created across ~350 unique users
- 1,000+ new repositories added every 30 minutes during initial campaign hours
- Affects packages from major ecosystems: Zapier, ENS Domains, PostHog, Postman, AsyncAPI, and more
- Multi-cloud credential theft (AWS, Azure, GCP)
- Docker privilege escalation attempts
Verified Credential Theft (from ~20,000 analyzed repos):
- 775 compromised GitHub access tokens
- 373 AWS credentials exposed
- 300 GCP credentials exposed
- 115 Azure credentials exposed
β οΈ Cross-Victim Exfiltration Warning
CRITICAL: Wiz Research has confirmed cross-victim exfiltration is occurring. This means:
- One victim's stolen secrets may be published to repositories owned by a different, unrelated victim
- If you find suspicious data in your GitHub repositories, it may belong to another compromised user
- Your data may have been exfiltrated to repositories you don't own
- This complicates attribution and incident response
Investigation Implication: When reviewing exfiltrated data in your repositories, verify whether the data actually belongs to your organization or another victim.
π Connection to Previous Attacks
This attack is directly linked to the August 2025 s1ngularity/Nx compromise, where initial GitHub token theft enabled the broader supply chain attack. Many initial Shai-Hulud victims were known victims of the s1ngularity attack. Security researchers also note the integration of AI-generated content within the campaign, with moderate confidence that an LLM was used to generate the malicious bash script.
π
Attack Timeline