Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Shai-Hulud 2.0 Cyberattack Compromises 30,000 Repos and Exposes 500 GitHub Accounts

The Shai-Hulud 2.0 supply chain attack has emerged as a significant malware campaign impacting the developer ecosystem. First detected on Fri, Nov 24, 2025, the attack has been closely monitored by Wiz Research and Wiz CIRT, revealing a continuous spread…

The Shai-Hulud 2.0 supply chain attack has emerged as a significant malware campaign impacting the developer ecosystem. First detected on Fri, Nov 24, 2025, the attack has been closely monitored by Wiz Research and Wiz CIRT, revealing a continuous spread despite reduced infection rates.

The attack's scope includes approximately 24,000 compromised environment.json files containing critical system and credential information. The malware affected over 30,000 repositories, with 70% containing unique victim environments.

Notably, the malware exfiltrated over 500 GitHub usernames and tokens, enabling further attacks across multiple GitHub accounts and organizations.

This attack is characterized by its persistence, with new repositories emerging even six days post-detection. GitHub Actions is the primary CI/CD platform targeted, followed by Jenkins, GitLab CI, and AWS CodeBuild.

A notable resurgence was observed on Fri, Dec 1, 2025, with over 200 new infected repositories identified within a 12-hour window. The malware employs a sophisticated infection methodology, utilizing stolen credentials to propagate across new victims, complicating incident response.

The Shai-Hulud 2.0 supply chain attack has emerged as a significant malware campaign impacting the developer ecosystem.
Henry Dalton · Thehackingpost

The attack primarily exploits the npm ecosystem with malicious packages, but it has also impacted other software delivery channels. Specifically, AsyncAPI reported the exfiltration of npm tokens and an OpenVSX API key, affecting the AsyncAPI IDE extension.

Furthermore, the malware extended into the Java/Maven ecosystem, though active spread in Maven Central or OpenVSX was not observed at the time.

The volume of stolen credentials poses an immediate threat for downstream attacks. Analysis indicates approximately 60% of leaked npm tokens remain valid, and around 2.5% of secrets in truffleSecrets.json files were verified by the malware.

Advertisement

Despite efforts to address the issue, companies continue to document infections, and confusion persists regarding GitHub Actions security controls. The Shai-Hulud 2.0 incident highlights critical vulnerabilities in supply chain security practices.

Organizations are advised to strengthen GitHub Actions configurations, implement secret management strategies, and maintain vigilant monitoring for compromised credentials. The threat remains active, with potential risks extending for months.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories