Cyber Security News

Zapier’s NPM Account Hacked – Multiple Packages Infected with Self-Propagating Shai Hulud Malware

A massive supply chain attack targeting the NPM accounts of automation giant Zapier and the Ethereum Name Service (ENS).

Identified by Aikido Security, the campaign is being orchestrated by the same threat actors responsible for the “Shai Hulud” self-propagating worm that first surfaced in September.

This latest wave, self-titled “Shai Hulud: The Second Coming,” has compromised multiple core packages and created over 19,000 public repositories containing stolen credentials.

The threat actor behind this campaign has pivoted from previous targets to inject malicious code directly into widely used dependencies within the Zapier and ENS ecosystems.

Unlike typical static malware, this attack uses a self-propagating worm that can rapidly expand. Once a developer installs an infected package, the malware activates to harvest sensitive secrets, including NPM tokens, GitHub Personal Access Tokens (PATs), and cloud infrastructure keys.

These stolen credentials are then immediately utilized to spread the infection further, creating a cascading effect across the open-source community. The speed of this propagation is alarming, with the impact surpassing the actor’s initial September campaign within just five hours of detection.

Data Exfiltration Tactics

The primary objective of this attack appears to be maximum disruption and data exposure. The malware employs TruffleHog, a tool designed to hunt for secrets, to exfiltrate sensitive data from infected environments.

The attackers are not just keeping these credentials to themselves. They are also sharing them publicly on GitHub in repositories with descriptive titles “Shai Hulud: The Second Coming.”

This public exposure exponentially increases the risk, as it allows other opportunistic threat actors to weaponize the exposed keys before organizations can rotate them, Aikido Security said to Cybersecurity News.

The sheer volume of created repositories suggests a highly automated execution meant to overwhelm security teams and incident responders.

The following packages have been confirmed as compromised and should be considered actively malicious.

EcosystemPackage NameStatus
Zapierzapier-platform-coreInfected / Malicious
Zapierzapier-platform-cliInfected / Malicious
Zapierzapier-platform-schemaInfected / Malicious
Zapier@zapier/secret-scrubberInfected / Malicious
ENS@ensdomains/ens-validationInfected / Malicious
ENS@ensdomains/content-hashInfected / Malicious
ENSethereum-ensInfected / Malicious
ENS@ensdomains/react-ens-addressInfected / Malicious
ENS@ensdomains/ens-contractsInfected / Malicious
ENS@ensdomains/ensjsInfected / Malicious
ENS@ensdomains/ens-archived-contractsInfected / Malicious
ENS@ensdomains/dnssecoraclejsInfected / Malicious

Organizations utilizing any of the listed packages must assume a full compromise of their development environments. Security teams are urged to immediately rotate all GitHub, NPM, and cloud credentials to prevent unauthorized access.

It is critical to audit all dependencies and specifically scan GitHub organizations and employee accounts for repositories matching the “Shai Hulud” description.

To halt further spread, DevOps teams should temporarily disable NPM postinstall scripts in CI/CD pipelines where possible and enforce Multi-Factor Authentication (MFA) for all package maintainers.

Locking dependency versions and utilizing tools like SafeChain can help block the automatic execution of this malware while the ecosystem recovers.

Indicator TypeValue / Description
Repo Name PatternShai Hulud: The Second Coming
Malware BehaviorAutomated execution of TruffleHog for secret scanning
Targeted AssetsNPM Tokens, GitHub PATs, Cloud Keys
Public Repo Count> 19,000 malicious repositories created

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

1 hour ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

11 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

12 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

12 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

12 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

13 hours ago