Skip to main content
Shai-Hulud: Self-Replicating npm Post-Install Worm Harvesting CI/CD Secrets operation cover
COMING SOONAdvancedPRO

Shai-Hulud: Self-Replicating npm Post-Install Worm Harvesting CI/CD Secrets

A routine dependency bump on a shared Linux CI runner pulls a trojanized npm package whose postinstall hook runs a bundled worm. The worm harvests GitHub, npm, and cloud credentials from the filesystem and the Instance Metadata Service, verifies them with TruffleHog, exfiltrates the loot to a free webhook dropbox, then reuses the stolen tokens to flip private repositories public as '-migration' clones, create a public Shai-Hulud loot repository, and republish itself into the organization's own packages. Reconstruct the self-replicating supply chain compromise from endpoint XDR and egress firewall telemetry, and classify the key ATT&CK techniques.

1h 15m
8 tasks
150 points
Pro

Launches in 3 days

Sep 1, 2026

Tuesday, September 1, 2026 at 9:00 AM

View Pro plans

Pro unlocks this operation at launch.

Training Tools

XDRFirewall

What you'll investigate

8 objectives unlock when this operation goes live.

1Incident brief
2Find the file the install executed
3Recover the payload's huntable indicator
4Classify the install-time execution
5Separate the exfiltration from the build traffic
6Classify the metadata-service credential theft
7Recover the leaked private repository
8Classify the self-propagation step

Be first when it launches

Create your account and grab Pro before launch. The moment this operation goes live on Sep 1, 2026, you can jump straight in.

Get Started Free