Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Shai-Hulud npm Worm, First Wave (September 2025): How…
Breach analysis Incident: 15 Sep 2025

Shai-Hulud npm Worm, First Wave (September 2025): How Stolen npm Tokens Turned tinycolor Into a Self-Spreading Credential Stealer

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 10 min read
On this page

On 15 September 2025, malicious versions of the popular npm package @ctrl/tinycolor and dozens of others appeared on the registry carrying a self-replicating worm later named Shai-Hulud. When a developer or CI job installed an infected package, the worm ran TruffleHog to hunt for secrets, used any npm token it found to publish trojanised versions of that maintainer's other packages, and pushed a GitHub Actions workflow that sent repository secrets to an attacker endpoint. Stolen data was dumped into public GitHub repositories named "Shai-Hulud". Packages published by CrowdStrike's npm account were among those hit. Counts grew from about 40 to 187 within a day, and GitHub later said it removed more than 500 compromised packages. This was the first wave of the campaign. A larger second wave in November 2025 is covered on a separate page. How the first maintainer account was compromised has not been confirmed.

Key takeaways

  • Malicious versions of @ctrl/tinycolor, a package with over 2 million weekly downloads, and other packages were published on 15 September 2025, according to StepSecurity and Wiz. GitHub said it removed more than 500 compromised packages.
  • The worm spread through publishing identities: it took npm tokens from ~/.npmrc or environment variables, listed the maintainer's other packages and published infected versions of them.
  • GitGuardian counted 278 secrets leaked publicly in the first phase, mostly GitHub tokens, npm tokens and AWS keys, and found 37 still valid after the initial clean-up.
  • Wiz found eight users whose private repositories had been copied to public ones. CrowdStrike said the affected packages were not used in its Falcon sensor and that it rotated its registry keys.
  • The identity lesson: a long-lived publishing token on a developer machine is a key to every package that developer maintains, so one infection can become hundreds.

At a glance

Organisationsnpm package maintainers, starting with @ctrl/tinycolor and including packages published by CrowdStrike's npm account; developers and CI pipelines that installed the infected versions
WhenMalicious versions published 15 September 2025; most GitHub activity between 15 and 16 September 2025; GitHub announced npm hardening on 22 September and CISA issued an alert on 23 September 2025
AttackerUnknown. The campaign is named after the "Shai-Hulud" repositories and workflow files the malware created
Entry pointTrojanised npm package versions that ran a bundled script during installation; how the first maintainer account was compromised has not been confirmed
Identities abusednpm publishing tokens, GitHub personal access tokens and GitHub Actions secrets, AWS, GCP and Azure credentials found on developer machines and CI runners
ImpactHundreds of npm packages trojanised (GitHub says 500+ removed); 278 secrets leaked publicly in the first phase according to GitGuardian; some private repositories made public
CategoryNHI. Incident class: confirmed NHI breach (stolen publishing and cloud credentials used to spread malware and leak secrets)

What happened

"On September 15, 2025, malicious versions of multiple popular packages were published to npm," Wiz wrote the following day. StepSecurity, which published its analysis on 15 September, said the first and best known was @ctrl/tinycolor, a colour manipulation library that "receives over 2 million weekly downloads". BleepingComputer reported that Socket first counted about 40 affected packages, and that Socket and Aikido raised the total to 187 by 16 September, including several packages published under CrowdStrike's npm account. CISA later described the worm as having compromised "over 500 packages".

Each infected package carried a large minified script, bundle.js, that ran when the package was installed. StepSecurity found that it dumped environment variables, queried AWS Secrets Manager and GCP Secret Manager, and downloaded and ran TruffleHog, a legitimate secret scanner, to search the filesystem for keys. If it found an npm token, it listed the other packages that token's owner maintained, injected itself into them and published new versions. StepSecurity said "the malware includes a self-propagating mechanism that automatically infects downstream packages". The script also used GitHub tokens to create a branch named shai-hulud with a workflow that sent the repository's secrets to an external webhook, and uploaded what it had collected to a new repository named Shai-Hulud. StepSecurity noted that "The repository is public by default to ensure easy access for the command and control infrastructure."

Wiz initially found 36 GitHub users with secrets exposed in Shai-Hulud repositories and eight users whose private repositories had been republished as public copies with a "-migration" suffix. GitGuardian tracked the GitHub activity from 03:46 on 15 September to 13:42 on 16 September and counted 226 malicious workflow files, 44 uploaded data files and 278 leaked secrets, of which 90 came from local machines and 188 from malicious workflows. It said new victims appeared again from 18:00 on 16 September, after the first phase ended.

CrowdStrike told BleepingComputer: "These packages are not used in the Falcon sensor, the platform is not impacted and customers remain protected." It said it had removed the packages and rotated its keys in public registries. GitHub said it was notified of the attack on 14 September 2025, removed the compromised packages and began blocking uploads containing the malware's indicators of compromise. On 22 September it set out changes to npm publishing: required two-factor authentication for local publishing, granular tokens with a limited lifetime of seven days, wider use of trusted publishing and the deprecation of classic tokens. Researchers had not confirmed how the first maintainer account was compromised.

Timeline

DateEvent
14 September 2025GitHub says it was notified of the Shai-Hulud attack.
15 September 2025Malicious versions of @ctrl/tinycolor and other packages are published to npm; StepSecurity publishes the first analysis.
16 September 2025BleepingComputer reports 187 affected packages, including CrowdStrike's; Wiz and GitGuardian publish their findings.
22 September 2025GitHub reports removing more than 500 compromised packages and announces npm publishing changes.
23 September 2025CISA issues an alert urging credential rotation and phishing-resistant MFA for developer accounts; GitGuardian adds the leaked secrets to its HasMySecretLeaked lookup.
24 November 2025A second, larger Shai-Hulud wave begins, covered on a separate page.

How it happened: the identity attack path

  1. First publishing identity compromised. An attacker gained the ability to publish @ctrl/tinycolor and other packages. How that first account or token was obtained has not been confirmed.
  2. Code runs at install time. Developers and CI jobs that installed an infected version ran bundle.js with their own privileges.
  3. Secrets harvested. The script collected environment variables, cloud secret manager contents and files found by TruffleHog, including npm tokens, GitHub tokens and AWS keys.
  4. Tokens reused to spread. Each npm token found was used to publish trojanised versions of the token owner's other packages, which is what made the attack a worm.
  5. Secrets published and piped out. GitHub tokens were used to create public Shai-Hulud repositories holding the stolen data and to push workflows that sent repository secrets to a webhook. Some private repositories were made public.

Impact

  • Confirmed: hundreds of npm packages trojanised; GitHub says it removed more than 500. Packages published by CrowdStrike's npm account were among them, though CrowdStrike said its platform was not affected.
  • Confirmed secret exposure: GitGuardian counted 278 secrets leaked publicly in the first phase, with 37 still valid after most were revoked. Wiz found eight users whose private repositories were made public.
  • Potential: any credential on an infected developer machine or CI runner, including cloud keys and secret manager contents, should be treated as stolen, since the worm also sent data to an external endpoint.
  • Wider: the wave led GitHub to shorten npm token lifetimes and push trusted publishing, and it was followed by a larger second wave in November 2025.

What this means for NHI governance

Shai-Hulud is an identity attack dressed up as malware. The code itself was ordinary: it read files, called a secret scanner and made API calls. What turned it into a worm was the npm publishing token sitting on developer machines and in CI, with rights over every package its owner maintained and no expiry. Each stolen token gave the attacker a new set of packages to infect, and each infected package harvested more tokens. GitHub tokens did the same for repositories, and cloud keys found along the way widened the damage beyond the npm ecosystem.

The fixes GitHub announced are the standard NHI answers: short-lived, narrowly scoped tokens, publishing through trusted publishing so no long-lived token sits in the build system, and strong MFA for the humans who can still publish. Organisations should also treat install-time scripts as code execution with the developer's full identity. See our CI/CD Pipeline Identity Security Guide and Secrets Management Guide.

Recommendations

  • Move publishing to trusted publishing. Publish from CI using short-lived OIDC credentials so there is no long-lived npm token to steal. See our CI/CD Pipeline Identity Security Guide.
  • Rotate every credential an infected install could reach. Include npm, GitHub, cloud, SSH and CI secrets, not only the npm token. See the Leaked Credential Response Playbook.
  • Keep secrets out of developer files and environment variables. Use a secrets manager with short-lived access instead of .npmrc tokens and plain environment variables. See our Secrets Management Guide.
  • Restrict install scripts in CI. Disable lifecycle scripts where they are not needed, and pin dependencies to known good versions as CISA advised.
  • Hunt for the worm's traces. Look for shai-hulud branches, unexpected workflow files, new public repositories and "-migration" copies in your GitHub organisation.
  • Require phishing-resistant MFA for maintainers. Protect the human accounts that can still publish or create tokens. See our MFA Guide.

Frequently asked questions

What was the first Shai-Hulud npm attack?

It was a self-replicating worm published to npm on 15 September 2025, starting with @ctrl/tinycolor. Infected packages stole secrets from the machines that installed them and used stolen npm tokens to publish infected versions of other packages. GitHub said it removed more than 500 compromised packages.

How is the September 2025 wave different from the November 2025 Shai-Hulud attack?

The September wave ran a bundle.js script with TruffleHog and dumped stolen data into repositories named Shai-Hulud, with some private repositories made public. The November 2025 wave was a separate, larger campaign that hit different packages and reached more than 25,000 GitHub repositories.

Was CrowdStrike breached by Shai-Hulud?

Packages published through CrowdStrike's npm account were infected. CrowdStrike said they were not used in its Falcon sensor, that its platform was not affected, and that it removed the packages and rotated its keys in public registries.

Shai-Hulud npm Worm 2025 (second wave) · Nx s1ngularity Attack 2025 · GhostAction Campaign 2025 · Mini Shai-Hulud 2026 · CI/CD Pipeline Identity Security Guide

How NHI Mgmt Group can help

Package publishing tokens, CI secrets and cloud keys on developer machines are non-human identities that rarely have an owner or an expiry date. We help teams find them, move publishing to short-lived credentials and build a response plan for the day a dependency turns hostile. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org