Join our Newsletter — 33% off our NHI Course

Static secrets in npm supply chains: what should teams change now?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Shai-Hulud spread through the npm ecosystem by harvesting static secrets from infected packages, then using stolen GitHub, npm, and cloud credentials to propagate further, according to Defakto Security. The incident shows that key rotation alone cannot contain a worm when permanent credentials still carry standing privilege and broad blast radius.

Editorial analysis by NHI Mgmt Group, based on content published by Defakto Security: “Shai-Hulud npm Supply Chain Attack: Why Secrets Fueled the Worm”.

By the numbers:

  • The worm spread through more than 300 compromised packages in days.
  • Early reporting put the number of infected packages around 180-200.

Key questions

Q: What breaks when static secrets are used in npm supply chains?

A: Static secrets turn a supply chain compromise into a propagation event because the same credential can be reused to publish malicious packages, access repositories, and reach cloud services.

Q: Why do long-lived automation tokens increase supply chain risk?

A: They increase risk because a stolen token remains valid long enough to be copied, reused, and chained into additional compromise steps.

Q: What signs suggest a build or publishing flow is overexposed?

A: Look for credentials stored in environment variables, shared config files, developer machines, or metadata services, especially when the same identity can publish code and reach cloud resources.

Practitioner guidance

  • Eliminate reusable publish tokens Replace long-lived npm, GitHub, and cloud automation tokens with short-lived identities issued at runtime for each publishing or build task.
  • Inventory secret-bearing build paths Trace where environment variables, metadata services, and local files expose credentials in developer and CI/CD environments, then remove the highest-value exposures first.
  • Bind automation to task scope Limit each non-human identity to one publishing or deployment purpose so a stolen credential cannot be reused across repos, workflows, and cloud services.

Bottom line: Shai-Hulud exposed a supply chain weakness in which static secrets enabled a package worm to spread beyond the initial infection point.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 5 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Static secrets create a propagation layer, not just an exposure layer. Once a token can be reused across package publishing, source control, and cloud access, it becomes part of the attacker's distribution mechanism. Shai-Hulud showed that the compromise path does not stop at theft; the same credential can be used to publish more malware and widen the blast radius. Practitioners should treat every persistent secret as a possible propagation asset.

A few things that frame the scale:

  • 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: Should teams prioritise key rotation or dynamic identity for package publishing?

A: Dynamic identity should come first when package publishing or CI/CD relies on reusable secrets with broad reach. Rotation still leaves the organisation managing stored credentials and reacting after compromise. Ephemeral identities reduce the number of reusable secrets in circulation and remove the easiest path for worm propagation.

👉 Read our full editorial: Shai-hulud shows why static secrets still fuel supply chain worms


This post was modified 5 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.