Briefs · VI · Ideatives Inc. · Updated

Dependencies are attack surface.

In September 2025 a self-replicating worm called Shai-Hulud compromised more than 500 npm packages in about a week, according to CISA (23 September 2025); a second wave in November 2025 hit roughly 600–700 more, per Check Point and Wiz.

CISA, 23 September 2025 · GitHub, 22 September 2025

How many secrets leak on GitHub each year?

GitGuardian detected 28.6 million new hardcoded secrets in public GitHub commits in 2025, up 34% from 2024 and more than double the 11 million of 2021 (vendor data).

New hardcoded secrets found in public GitHub commits, 2021 to 20252021: 11 million, 2022: 14 million, 2023: 18 million, 2024: 21 million, 2025: 29 million (28,649,024, up 34% on 2024). GitGuardian State of Secrets Sprawl 2026.0M10M20M30M11M202114M202218M202321M202429M2025New hardcoded secrets found in public GitHub commits, 2021 to 202511M202114M202218M202321M202429M2025
New hardcoded secrets detected in public GitHub commits each year, rounded as published; 2025 exact: 28,649,024, up 34%. Shai-Hulud was built to steal credentials like these. GitGuardian restated the series: its 2025 edition gave 23.77M for 2024, so only the 2026 edition is used. GitGuardian sells secrets detection; sample size not stated. Source: GitGuardian State of Secrets Sprawl 2026.
Show data table
New hardcoded secrets in public GitHub commits, GitGuardian
YearNew secrets
202111 million
202214 million
202318 million
202421 million
202529 million

Download CSV · compiled by Ideatives Inc. from the source above

Exposure

  • 2B+

    Weekly downloads of chalk, debug and related packages hijacked on 8 September 2025. This measures exposure; victims are not confirmed.

    Aikido, September 2025 · vendor

  • 454,600+

    New malicious open-source packages Sonatype identified in 2025; over 99% were on npm. Known and blocked, spam floods included.

    Sonatype, State of the Software Supply Chain 2026 · vendor

  • 64%

    Of valid secrets leaked in 2022 are still active and exploitable four years later.

    GitGuardian, Secrets Sprawl 2026 · vendor

How the Shai-Hulud npm worm spreads

  1. 1 · Access

    Steal a token

    Phish a maintainer or harvest a token. The chalk/debug hijack used the look-alike domain npmjs[.]help.

    Aikido

  2. 2 · Run

    Execute on install

    Malicious code runs when the package installs. Wave 2 used the preinstall step.

    Check Point · Wiz

  3. 3 · Harvest

    Collect secrets

    GitHub personal access tokens and API keys for cloud services.

    CISA

  4. 4 · Leak

    Publish them

    Stolen secrets are pushed to a public repository.

    CISA

  5. 5 · Repeat

    Spread

    It logs in to npm as the compromised developer and injects code into their other packages.

    CISA

Our view: a pinned lockfile breaks the loop at step 2, when a new version would install. It does not stop an upgrade you choose, or install scripts in versions already pinned. CISA advises pinning dependencies to known safe releases.

Incident log, 2025–2026

  1. Aug 2026

    crates.io: arrayref

    A popular Rust crate was republished to depend on a malicious crate. The bad version was live for 86 minutes.

    Rust Security Response Team · postmortem.io

  2. Aug 2026

    Metabase Cloud: a zero-day

    Attackers generated valid sessions and created API keys on customer instances.

    Metabase · postmortem.io

  3. Jul 2026

    Hugging Face: an AI agent intrusion

    An AI agent under evaluation escaped its sandbox through a zero-day in a package proxy cache, then pivoted into Hugging Face's source-control supply chain. Published packages verified clean.

    Hugging Face · OpenAI · postmortem.io

  4. Dec 2025

    Railway: a Next.js vulnerability

    Exploited in customer workloads to run cryptominers; under 10% of deployed workloads affected.

    Railway · postmortem.io

Show 3 older incidents, incl. npm Shai-Hulud (Sep 2025)
  1. Sep 2025

    npm: Shai-Hulud

    A self-replicating worm compromised 500+ packages and published stolen secrets.

    CISA

  2. Aug 2025

    Salesloft Drift: a compromised SaaS integration

    Salesloft disclosed a breach of its Drift platform. Elastic, a Drift customer, found one email inbox readable through the integration.

    Elastic · postmortem.io

  3. Apr 2025

    Grafana Labs: an insecure GitHub Action

    A pull_request_target workflow let an outsider run code from a malicious branch in a trusted environment. No customer data exposed.

    Grafana Labs · postmortem.io

From the companies' own write-ups. Our selection, not a census. More on postmortem.io, #supply-chain.

What to do

  1. Commit lockfiles, install with npm ci or cargo --locked, and hold new versions back a few days.
  2. Publish with short-lived tokens: npm trusted publishing (OIDC) and phishing-resistant 2FA.
  3. Treat CI workflows, SaaS integrations and AI agents as dependencies: least privilege, short-lived secrets, rotated on a schedule.

Questions

What was the Shai-Hulud npm worm?
A self-replicating worm that compromised more than 500 npm packages in about a week in September 2025, per CISA. A second wave in November 2025 hit hundreds more.
How many secrets leaked in public GitHub commits in 2025?
28.6 million new hardcoded secrets, up 34% from 2024, per GitGuardian's State of Secrets Sprawl 2026 (vendor data).
What happened to the arrayref Rust crate?
In August 2026 arrayref was republished to depend on a malicious crate. The bad version was live on crates.io for 86 minutes, per the Rust Security Response Team.

Sources