Toutes les vulnérabilités
CRITICALSupply chainexploited in the wild

NPM-SHAI-HULUD-2-2025

npm · @asyncapi/*, @posthog/*, Zapier, ENS packages (Shai-Hulud 2.0)

Résumé

A renewed wave of the Shai-Hulud worm, dubbed Shai-Hulud 2.0 or 'The Second Coming', began around November 21-24, 2025 and affected tens of thousands of GitHub repositories across roughly 350 unique users. The variant moved execution to the pre-install phase, dropped large heavily obfuscated payloads (setup_bun.js and bun_environment.js), and exfiltrated stolen secrets to public GitHub repositories described as 'Sha1-Hulud: The Second Coming'. As an aggressive fallback, it attempted to destroy the victim's entire home directory if credential theft failed.

Références

Vulnérabilités liées

Tout Supply chain →