← Back

Wire · opportunities

Fast-Moving Shai-Hulud Attack Infects npm Packages with 2 Billion Monthly Downloads

Published

4 August 2026

Topic

opportunities

Sectors

Enterprise SoftwareDeveloper Tools

Source

Read at devops.com

Verified

Fusion42 · 1 September 2026 · Fusion42 review

A widespread Shai-Hulud supply chain attack has compromised over 1,280 npm packages with 2+ billion monthly installs by hijacking a maintainer's GitHub account to publish malicious updates that steal sensitive credentials. The malware spreads rapidly, infecting 50 to 100 new packages every few minutes and impacting packages linked to companies such as Deliveroo, OneReach, ServiceTitan, Picsart, and Qlik.

This Wire brief sits within Fusion42's coverage of Enterprise Software and Developer Tools.

◆ The Wire takeaway

This npm supply chain breach slams enterprise software founders building on open-source packages. You need to immediately audit your npm dependencies and control your CI/CD secrets before your build pipeline becomes a spread vector.

Coverage

1 source · 4 Aug 2026

Related on Wire

Topics

Enterprise SoftwareDeveloper Toolssupply-chain-attacknpmmalwarecredentials-theftsoftware-security