Netskope Threat Labs

Shai-Hulud

ATP Sandbox Adv. HeuristicsAV

Shai-Hulud is a self replicating worm that spreads through package registries and developer toolchains, and the worm plants itself in code repositories and build systems. Its campaigns stole credentials and secrets from developer environments and used them to push infected packages onward, creating a chain of compromise that spread without user interaction. Researchers analyzed one of its major waves, and the family has become a reference point for supply chain worm risks in software ecosystems.

First seen
September 2025
Last seen
October 2026
ShaiHuludShaiWorm

33 techniques across 15 tactics.

TA0043 Reconnaissance

TA0042 Resource Development

TA0001 Initial Access

  • T1195Supply Chain Compromise
    • T1195.001Compromise Software Dependencies and Development Tools

TA0002 Execution

TA0003 Persistence

TA0004 Privilege Escalation

TA0005 Stealth

TA0006 Credential Access

TA0007 Discovery

  • T1082System Information Discovery

TA0008 Lateral Movement

  • T1550Use Alternate Authentication Material

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel
  • T1567Exfiltration Over Web Service

TA0040 Impact

TA0112 Defense Impairment

  • T1553Subvert Trust Controls
  • T1685Disable or Modify Tools
Alert Name
Archive-GZIP.Worm.ShaiHulud
Archive-TAR.Worm.ShaiHulud
ByteCode-JAVA.Downloader.ShaiHulud
Generic.GYP.ShaiHulud.A.2F5F684B
Generic.GYP.ShaiHulud.A.B2F39846
Generic.JS.ShaiHulud.D.01D106D4
Generic.JS.ShaiHulud.D.0E560126
Generic.JS.ShaiHulud.D.8BBEC53A
Generic.JS.ShaiHulud.D.C1DBFEC1
Generic.JS.ShaiHulud.D.D58325BD