Wire · opportunities
Fast-Moving Shai-Hulud Attack Infects npm Packages with 2 Billion Monthly Downloads
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 1 September 2026 · Fusion42 review
A widespread Shai-Hulud supply chain attack has compromised over 1,280 npm packages with 2+ billion monthly installs by hijacking a maintainer's GitHub account to publish malicious updates that steal sensitive credentials. The malware spreads rapidly, infecting 50 to 100 new packages every few minutes and impacting packages linked to companies such as Deliveroo, OneReach, ServiceTitan, Picsart, and Qlik.
This Wire brief sits within Fusion42's coverage of Enterprise Software and Developer Tools.
◆ ◆ The Wire takeaway
This npm supply chain breach slams enterprise software founders building on open-source packages. You need to immediately audit your npm dependencies and control your CI/CD secrets before your build pipeline becomes a spread vector.
◆ Coverage
1 source · 4 Aug 2026
◆ Related on Wire
◆ Topics