GitLab Identifies Large-Scale npm Supply Chain Attack with Destructive Malware
By
OuterVale
Hot, fresh, and worth queueing round the block for.
Summary
GitLab's security researchers have uncovered a large-scale supply chain attack in the npm ecosystem involving a destructive malware variant called 'Shai-Hulud'. The malware exhibits worm-like propagation behavior that automatically infects additional packages maintained by impacted developers and contains a critical 'dead man's switch' mechanism that threatens to destroy user data if its propagation is disrupted. The attack represents a significant threat to the software supply chain with potentially widespread consequences.
Key quotes
· 4 pulledGitLab's Vulnerability Research team has identified an active, large-scale supply chain attack involving a destructive malware variant spreading through the npm ecosystem.
Our internal monitoring system has uncovered multiple infected packages containing what appears to be an evolved version of the 'Shai-Hulud' malware.
Early analysis shows worm-like propagation behavior that automatically infects additional packages maintained by impacted developers.
Most critically, we've discovered the malware contains a 'dead man's switch' mechanism that threatens to destroy user data if its propagation and
You might also wanna read
Microsoft uncovers supply chain attack: Compromised @antv npm packages steal CI/CD credentials via Mini Shai-Hulud malware
Microsoft has identified an active supply chain attack targeting the @antv npm package ecosystem. A threat actor compromised an @antv mainta

September 2025 NPM supply-chain attack compromises popular JavaScript packages
In September 2025, a coordinated software supply-chain attack targeted multiple popular NPM packages in the JavaScript ecosystem. The attack
Microsoft uncovers npm supply chain attack stealing cloud and CI/CD credentials via typosquatted packages
Microsoft identified an active supply chain attack (Mini Shai-Hulud campaign) targeting the npm package ecosystem. On May 28, 2026, a threat
AI-Generated npm Package Leaks Its Own GitHub Token, Exposing Malware Operator
A malicious npm package named mouse5212-super-formatter, identified by OX Security, was caught leaking its own hardcoded GitHub token. This
npm malware targeting Claude users leaks own GitHub token, reaches 676 downloads
An npm package called "mouse5212-super-formatter" targeting Claude users acted as information-stealing malware, reaching 676 downloads befor
176 malicious npm packages used dependency confusion to target internal dependencies and steal credentials
Sonatype researchers uncovered a campaign involving 176 malicious npm packages using a dependency confusion attack strategy. Attackers publi
