npm Package Engagement Campaign – 11/25



Good morning

In order to facilitate the adoption of verification, containment, and eradication measures, we share the following detailed information about acontinuous and large-scale supply chain attack affecting the npm ecosystem and the JavaScript development community at large:

Context of the threat



Alert Level: 5 Criticism



Scope: Transversal

Motivation: Economic

Start of activity:November 2025

Geographical relevance: Global

Active campaigns: Yes

Relevant threat information

  • Description

TheShai Hulud campaign, an attack that took advantage of compromised project maintainer accounts to insert malicious code into npm packages,has been reactivated with a significant new offensive against the supply chain of the JavaScript ecosystem. According to the most recent reports, actors have initiated a new wave of infections targetingnpm packages with the aim of compromising integrations and project repositories hosted on GitHub, on a larger scale than the original campaign detected in late summer 2025.

The new indications suggest that the attackers have managed to compromise and inject malicious code into some500 npm packages with more than 132 million total monthly downloads, using manipulated versions to steal secrets, credentials and access keys linked to development and CI/CD environments. Notable targets include components used in large-scale environments, including projects linked to Zapier, ENS Domains, and Postman, confirming that the campaign is evolving and raising its level of operational impact.

The malicious code deployed in this new wave continues to take advantage of scripts that run during installation or execution processes, and establishes exfiltration mechanisms that send stolen secrets to infrastructure controlled by the attackers. The stolen data includes GitHub tokens, SSH keys, environment variables, configuration secrets, cloud service credentials, and any other information that could facilitate lateral movements or additional compromises.

In parallel, the actor is using compromised repositories to deploy manipulatedGitHub Actions workflows , thus automating the collection and sending of secrets, and maintaining persistence until maintainers detect the activity. This use of malicious automation evidences an increasing operational maturity compared to the original campaign.

Affectation

The scope of the new campaign is substantially higher than that recorded last September. Recent research confirms that approximately 500 npm packets have been altered, many of which have a high transitive dependence. This implies that, in addition to a higher volume of compromised packages than in the previous campaign, this wave affects components used in real processes, including automations, corporate integrations and internal flow tools supported by engineering teams. As a result, the risk of engagement is exponentially amplified in projects that were not even direct targets.



Among the ecosystems affected are continuous production and integration environments based on GitHub, impacting workflows that use contaminated repositories or manipulated dependencies. Confirmed infections in organizations such as Zapier, ENS Domains, and Postman highlight that the campaign is not limited to small packages, but affects widely adopted services and infrastructure.



Despite GitHub and npm's efforts to remove packages and block compromised accounts, the self-propagating nature of the attack means that full detection remains ongoing and that a definitive limit of the total impact is not yet available.



  • Threat prognosis

Everything indicates that the actor continues to be active and with expanding capacities. The current evidence shows:



  • Repeated publication of malicious versions using npm publish --force.

  • Continuous regeneration of compromised packets even after npm removes them.

  • Creation or manipulation of GitHub repositories to introduce malicious workflows capable of exfiltrating secrets and executing commands from the development environment.

  • Refined techniques to avoid detection, including more advanced obfuscation and the use of temporary or dynamically generated exfiltration services.

  • Expanded focus to high-profile ecosystems and companies, suggesting that the actor could be prioritizing strategic impact and mass capture of credentials.



In view of the intelligence collected, it is highly likely that new iterations of the campaign will continue to appear in the coming months, taking advantage of similar or evolved vectors.



Recommendations

As a good preventive practice in the face of this type of campaign, the Cybersecurity Agency of Catalonia identifies that it is a priority to implement quarantines of 60/90 days for updates of NPM packages and in general to dependencies in a transversal way. In a high number of campaigns of this type we find that with a quarantine policy a high number of campaigns of this type are avoided. Additionally, given the impact that an attack of these characteristics could have,it is also recommended to carry out the following actions:



  • Audit and clean up npm dependencies

  • Review all package.json, package-lock.json, and SBOM files to identify forward and transitive dependencies.

  • Remove or replace any packages marked as malicious or removed from the npm registry.

  • Revoke credentials from sensitive systems

  • Immediately revoke npm tokens, GitHub personal access tokens, SSH keys, and cloud provider keys that may have been exposed on developer machines or CI/CD pipelines.

  • Reissue new credentials with least privileges and enable multi-factor authentication (MFA).

  • Inspect GitHub repositories and CI/CD environments

  • Find and remove unexpected workflows or suspicious confirmations in GitHub Actions.

  • Check the creation of recent public repositories in your organization's GitHub accounts.

  • Strengthen development and CI/CD environments

  • Apply endpoint protection, full disk encryption, and security updates to all developer workstations (Linux/macOS).

  • Restrict npm installations from unverified sources and enforce strict minimum privileges for CI tokens.

  • Store all confidential information in secure secrets managers instead of using environment variables.



You can find a list of packages that have been identified as altered so far in the attached .txt.We remain at your disposal in case you have any doubts or need support in this regard.



Details

Documents

Comments

CERCA Ecosystem Information

CERCA Ecosystem Information

CERCA Communities
DEEPTECH Area