Sandworm In The Supply Chain: Lessons From The Shai-Hulud Npm Attack On Developer And Machine Identities
CyberArk, Wednesday, September 24th, 2025
Do you know why Shai-Hulud should raise your hackles? Unless you've spent time on Arrakis in Frank Herbert's Dune or the npm ecosystem this month, the name Shai-Hulud might not ring a bell.
In Herbert's world, Shai-Hulud is the colossal sandworm of Arrakis-feared, powerful, and destructive. In our world, I guess you could say the same thing.
Shai-Hulud surfaced as a malware worm that tore through the npm software registry on Sept. 16-17, 2025. Like its literary namesake, burrowing unseen, this worm tunneled into the supply chain, stealing developer credentials, API keys, and sensitive tokens. Attacks on package managers like npm, Homebrew, Yum, Chocolatey, and others are nothing new.