# SHA1-Hulud, npm supply chain incident

DevFeed: [SHA1-Hulud, npm supply chain incident](<https://devfeed.tech/articles/sha1-hulud-npm-supply-chain-incident-8097.md>)

Original publisher: [Read original article](<https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/>)

Author: Brian Vermeer

Published: 2025-11-24T18:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>), [npm](<https://devfeed.tech/topics/npm.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Azure](<https://devfeed.tech/topics/azure.md>), [Google Cloud Platform (GCP)](<https://devfeed.tech/topics/google-cloud.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci](<https://devfeed.tech/tags/ci.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-infrastructure](<https://devfeed.tech/tags/cloud-infrastructure.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [incident](<https://devfeed.tech/tags/incident.md>), [npm](<https://devfeed.tech/tags/npm.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [sha1-hulud](<https://devfeed.tech/tags/sha1-hulud.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [trust](<https://devfeed.tech/tags/trust.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>), [worm](<https://devfeed.tech/tags/worm.md>)

## AI overview

Snyk reports SHA1-Hulud, a second-wave npm supply chain attack and worm that spreads through trojanized packages with hidden preinstall scripts. The worm can compromise GitHub Actions self-hosted runners, inject malicious workflows, execute remote commands, exfiltrate GitHub and npm secrets, and search for AWS, Azure, and GCP credentials. Snyk identified more than 600 impacted npm packages and is retesting customer assets, notifying affected customers, and updating its vulnerability databases.

## Source excerpt

Snyk identified a new supply chain attack in the npm ecosystem, referred to as SHA1-Hulud. We believe this is a second wave of the Shai-Hulud attack. Learn what this attack is and how Snyk is responding.