Definition

Shai-Hulud is a credential-stealing, self-propagating malware family targeting the npm ecosystem. Variants (including Mini Shai-Hulud and miasma-worm) use install-time hooks, stolen publish tokens, and often valid trusted-provenance attestations to spread across maintainer graphs.

Key Points

  • 2026-08-04 keyv wave: Compromised GitHub account of jaredwray (keyv/cacheable family); malicious releases with GitHub Actions provenance; Bun-based loader (setup.mjsMath_Symbol.js) (2026-08-04-npm-shai-hulud-keyv-supply-chain-attack)
  • Package counts same-day: Aikido 434 → 868 → 1,280+ packages; 50–100 new every few minutes per DevOps.com/Aikido (2026-08-04-devops-shai-hulud-1280-packages)
  • Combined exposure claimed 2B+ monthly installs
  • Prior waves: late-2025 emergence; May–June 2026 miasma-worm (Red Hat, Microsoft GitHub)
  • Motivated npm v12 defaults blocking install scripts

Package/version totals are evolving same-day. Always timestamp-attribute counts from Aikido/Wiz/Socket/Snyk.

Sources