Shai Hulud 2.0 Supply Chain Compromise

Release Date: 24th of November 2025

Impact : HIGH / CRITICAL

TLP Rating: Clear

CERT Vanuatu (CERTVU) and the Department of Communication and Digital Transformation (DCDT) provide the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

Shai Hulud 2.0 is a self-propagating supply chain Malware targeting the NPM (Node Package Manager) ecosystem. It spreads through malicious NPM packages that execute lifecycle scripts to steal developer credentials and compromise Git-Hub, Git-Lab, Azure DevOps, and cloud services.

Read more

 

References

  1. https://about.gitlab.com/blog/gitlab-discovers-widespread-npm-supply-chain-attack/
  2. https://www.zscaler.com/blogs/security-research/shai-hulud-v2-poses-risk-npm-supply-chain