Definition
Shai-Hulud is a credential-stealing, self-propagating malware family targeting the npm ecosystem. Variants (including Mini Shai-Hulud and miasma-worm) use install-time hooks, stolen publish tokens, and often valid trusted-provenance attestations to spread across maintainer graphs.
Key Points
- 2026-08-04 keyv wave: Compromised GitHub account of
jaredwray(keyv/cacheable family); malicious releases with GitHub Actions provenance; Bun-based loader (setup.mjs→Math_Symbol.js) (2026-08-04-npm-shai-hulud-keyv-supply-chain-attack) - Package counts same-day: Aikido 434 → 868 → 1,280+ packages; 50–100 new every few minutes per DevOps.com/Aikido (2026-08-04-devops-shai-hulud-1280-packages)
- Combined exposure claimed 2B+ monthly installs
- Prior waves: late-2025 emergence; May–June 2026 miasma-worm (Red Hat, Microsoft GitHub)
- Motivated npm v12 defaults blocking install scripts
Package/version totals are evolving same-day. Always timestamp-attribute counts from Aikido/Wiz/Socket/Snyk.
Related
- miasma-worm
- supply-chain-attacks
- supply-chain-security
- trusted-provenance
- keyv
- npm
- bun
- npm-supply-chain-2026
- aikido-security
- wiz
- snyk
- socket