Briefs · VI · Ideatives Inc. · Updated
Dependencies are attack surface.
In September 2025 a self-replicating worm called Shai-Hulud compromised more than 500 npm packages in about a week, according to CISA (23 September 2025); a second wave in November 2025 hit roughly 600–700 more, per Check Point and Wiz.
How many secrets leak on GitHub each year?
GitGuardian detected 28.6 million new hardcoded secrets in public GitHub commits in 2025, up 34% from 2024 and more than double the 11 million of 2021 (vendor data).
Show data table
| Year | New secrets |
|---|---|
| 2021 | 11 million |
| 2022 | 14 million |
| 2023 | 18 million |
| 2024 | 21 million |
| 2025 | 29 million |
Download CSV · compiled by Ideatives Inc. from the source above
Exposure
2B+
Weekly downloads of chalk, debug and related packages hijacked on 8 September 2025. This measures exposure; victims are not confirmed.
Aikido, September 2025 · vendor
454,600+
New malicious open-source packages Sonatype identified in 2025; over 99% were on npm. Known and blocked, spam floods included.
Sonatype, State of the Software Supply Chain 2026 · vendor
64%
Of valid secrets leaked in 2022 are still active and exploitable four years later.
GitGuardian, Secrets Sprawl 2026 · vendor
How the Shai-Hulud npm worm spreads
1 · Access
Steal a token
Phish a maintainer or harvest a token. The chalk/debug hijack used the look-alike domain npmjs[.]help.
Aikido
2 · Run
Execute on install
Malicious code runs when the package installs. Wave 2 used the preinstall step.
Check Point · Wiz
3 · Harvest
Collect secrets
GitHub personal access tokens and API keys for cloud services.
CISA
4 · Leak
Publish them
Stolen secrets are pushed to a public repository.
CISA
5 · Repeat
Spread
It logs in to npm as the compromised developer and injects code into their other packages.
CISA
Our view: a pinned lockfile breaks the loop at step 2, when a new version would install. It does not stop an upgrade you choose, or install scripts in versions already pinned. CISA advises pinning dependencies to known safe releases.
Incident log, 2025–2026
Aug 2026
crates.io: arrayref
A popular Rust crate was republished to depend on a malicious crate. The bad version was live for 86 minutes.
Aug 2026
Metabase Cloud: a zero-day
Attackers generated valid sessions and created API keys on customer instances.
Jul 2026
Hugging Face: an AI agent intrusion
An AI agent under evaluation escaped its sandbox through a zero-day in a package proxy cache, then pivoted into Hugging Face's source-control supply chain. Published packages verified clean.
Dec 2025
Railway: a Next.js vulnerability
Exploited in customer workloads to run cryptominers; under 10% of deployed workloads affected.
Show 3 older incidents, incl. npm Shai-Hulud (Sep 2025)
Sep 2025
npm: Shai-Hulud
A self-replicating worm compromised 500+ packages and published stolen secrets.
CISA
Aug 2025
Salesloft Drift: a compromised SaaS integration
Salesloft disclosed a breach of its Drift platform. Elastic, a Drift customer, found one email inbox readable through the integration.
Apr 2025
Grafana Labs: an insecure GitHub Action
A pull_request_target workflow let an outsider run code from a malicious branch in a trusted environment. No customer data exposed.
From the companies' own write-ups. Our selection, not a census. More on postmortem.io, #supply-chain.
What to do
- Commit lockfiles, install with npm ci or cargo --locked, and hold new versions back a few days.
- Publish with short-lived tokens: npm trusted publishing (OIDC) and phishing-resistant 2FA.
- Treat CI workflows, SaaS integrations and AI agents as dependencies: least privilege, short-lived secrets, rotated on a schedule.
Questions
- What was the Shai-Hulud npm worm?
- A self-replicating worm that compromised more than 500 npm packages in about a week in September 2025, per CISA. A second wave in November 2025 hit hundreds more.
- How many secrets leaked in public GitHub commits in 2025?
- 28.6 million new hardcoded secrets, up 34% from 2024, per GitGuardian's State of Secrets Sprawl 2026 (vendor data).
- What happened to the arrayref Rust crate?
- In August 2026 arrayref was republished to depend on a malicious crate. The bad version was live on crates.io for 86 minutes, per the Rust Security Response Team.
Sources
- CISA, Widespread Supply Chain Compromise Impacting npm Ecosystem, 23 September 2025. Government. CISA's two entries are the only non-vendor sources here.
- GitHub, Our plan for a more secure npm supply chain, 22 September 2025. GitHub runs npm.
- Aikido, npm debug and chalk packages compromised, September 2025. Vendor.
- Check Point, Shai-Hulud 2.0, November 2025. Vendor; counts 621 packages in wave 2.
- Wiz, Shai-Hulud 2.0, 24 November 2025. Vendor; counts about 700. Sonatype lists 49. They count different things at different times.
- Sonatype, State of the Software Supply Chain 2026, 28 January 2026. Vendor; known and blocked packages, not a census.
- GitGuardian, State of Secrets Sprawl 2026. Vendor; public GitHub commits, sample size not stated. Figures differ from the 2025 edition.
- CISA, xz-utils compromise (CVE-2024-3094), 29 March 2024. Earlier precedent: a backdoor in a core library.