Over 600 npm Packages Compromised by Shai-Hulud Malware

A significant malware attack known as Shai-Hulud has compromised over 600 npm packages since November 21, 2025. This attack targets developer credentials and wallet keys, impacting high-profile projects such as Zapier, ENS Domains, and Postman. The attack’s effects are expected to reach beyond just the affected npm packages, potentially impacting financial security through compromised cloud accounts and crypto assets. Early detection revealed exposure of sensitive data like credentials to GitHub, prompting immediate actions from Aikido Security to contain the threat.