# sha1-hulud

Published articles for sha1-hulud.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Attacks rewritten: Where malware enters the build

DevFeed: [Attacks rewritten: Where malware enters the build](<https://devfeed.tech/articles/attacks-rewritten-where-malware-enters-the-build-12892.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/attacks-rewritten-where-malware-enters-the-build>)

Published: 2026-04-07T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [malware](<https://devfeed.tech/tags/malware.md>), [package-malware](<https://devfeed.tech/tags/package-malware.md>), [security](<https://devfeed.tech/tags/security.md>), [sha1-hulud](<https://devfeed.tech/tags/sha1-hulud.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [solarwinds](<https://devfeed.tech/tags/solarwinds.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [teampcp](<https://devfeed.tech/tags/teampcp.md>)

### AI overview

This article explains how modern software supply chain attacks can affect production deployments, CI/CD clusters, developer workstations, and other systems. It describes the shift from exploiting known production vulnerabilities to injecting malicious code upstream through compromised maintainer accounts, package managers, and binary dependencies.

### Source excerpt

Modern supply chain attacks target CI, dev machines, and dependencies. Learn how building from source helps prevent malware and reduce risk.

## Impact of SHA1-Hulud: The Second Coming on the Mintlify CLI

DevFeed: [Impact of SHA1-Hulud: The Second Coming on the Mintlify CLI](<https://devfeed.tech/articles/impact-of-sha1-hulud-the-second-coming-on-the-mintlify-cli-31088.md>)

Original publisher: [Read original article](<https://www.mintlify.com/blog/sha1-hulud-the-second-coming>)

Author: Han Wang

Published: 2025-11-25T00:00:00Z

Content type: news

Language: en

Sources: [Mintlify Blog](<https://devfeed.tech/sources/mintlify-blog.md>)

Topics: [Command-line interface](<https://devfeed.tech/topics/cli.md>), [npm](<https://devfeed.tech/topics/npm.md>), [malicious packages](<https://devfeed.tech/topics/malicious-packages.md>), [Security](<https://devfeed.tech/topics/security.md>), [pnpm](<https://devfeed.tech/topics/pnpm.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [announcements](<https://devfeed.tech/tags/announcements.md>), [deprecated](<https://devfeed.tech/tags/deprecated.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [npm](<https://devfeed.tech/tags/npm.md>), [pnpm](<https://devfeed.tech/tags/pnpm.md>), [resolved](<https://devfeed.tech/tags/resolved.md>), [security](<https://devfeed.tech/tags/security.md>), [sha1-hulud](<https://devfeed.tech/tags/sha1-hulud.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>)

### AI overview

Mintlify reports that its CLI was briefly exposed to the SHA1-Hulud supply chain attack through compromised npm dependencies on November 24, 2025. The company says it resolved the issue within six hours, released CLI version 4.2.210, deprecated potentially affected versions, and provided remediation steps for users who installed or updated during the vulnerable window.

### Source excerpt

The Mintlify CLI was briefly exposed to a supply chain attack. Learn what happened, who was affected, and what actions to take. Resolved in 6 hours.

## SHA1-Hulud, npm supply chain incident

DevFeed: [SHA1-Hulud, npm supply chain incident](<https://devfeed.tech/articles/sha1-hulud-npm-supply-chain-incident-8097.md>)

Original publisher: [Read original article](<https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/>)

Author: Brian Vermeer

Published: 2025-11-24T18:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>), [npm](<https://devfeed.tech/topics/npm.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Azure](<https://devfeed.tech/topics/azure.md>), [Google Cloud Platform (GCP)](<https://devfeed.tech/topics/google-cloud.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci](<https://devfeed.tech/tags/ci.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-infrastructure](<https://devfeed.tech/tags/cloud-infrastructure.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [incident](<https://devfeed.tech/tags/incident.md>), [npm](<https://devfeed.tech/tags/npm.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [sha1-hulud](<https://devfeed.tech/tags/sha1-hulud.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [trust](<https://devfeed.tech/tags/trust.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>), [worm](<https://devfeed.tech/tags/worm.md>)

### AI overview

Snyk reports SHA1-Hulud, a second-wave npm supply chain attack and worm that spreads through trojanized packages with hidden preinstall scripts. The worm can compromise GitHub Actions self-hosted runners, inject malicious workflows, execute remote commands, exfiltrate GitHub and npm secrets, and search for AWS, Azure, and GCP credentials. Snyk identified more than 600 impacted npm packages and is retesting customer assets, notifying affected customers, and updating its vulnerability databases.

### Source excerpt

Snyk identified a new supply chain attack in the npm ecosystem, referred to as SHA1-Hulud. We believe this is a second wave of the Shai-Hulud attack. Learn what this attack is and how Snyk is responding.