Campaign · Open Source · · 1 day

Sha1-Hulud worm spread across npm packages

Sha1-Hulud "Second Coming" was a broad npm worm wave that compromised hundreds of packages beyond the separately tracked Zapier and ENS ecosystems, including major scoped groups such as @asyncapi, @posthog, @postman, @voiceflow, and @browserbasehq.

Draws together 2 incidents across 62 packages

Sha1-Hulud "The Second Coming" was a broad npm worm wave discovered on November 24, 2025. It followed the September Shai-Hulud pattern but moved faster, crossed more package scopes, and produced more public evidence of stolen credentials.

The package list quickly outgrew any single vendor story. StepSecurity tracked hundreds of affected npm packages, including major scoped groups such as @asyncapi, @posthog, @postman, @voiceflow, @accordproject, @browserbasehq, @actbase, @oku-ui, and @mcp-use. Zapier and ENS are modeled separately because their package boundaries and response evidence are cleaner.

The payload installed Bun, harvested local and CI secrets, and wrote stolen material into GitHub repositories created under compromised accounts. StepSecurity reported more than 21,000 public repositories within five hours, using the description Sha1-Hulud: The Second Coming. Persistence was explicit: the malware registered a self-hosted GitHub Actions runner named SHA1HULUD under $HOME/.dev-env, then used GitHub discussion workflow injection to keep execution available after the first package install. The destructive path mattered too. On non-CI Linux hosts the payload could shred writable files under the user's home directory, turning an install-time credential theft into a local data-loss event for some machines.

This campaign record carries the broad worm mechanics and the moving aggregate. Leaf records remain package-scoped where the affected ecosystem published official advisories or where package lists are compact enough for practical inventory work.

Notes

  • Legacy artifact note: 700+ npm package rows in StepSecurity affected-package list
  • Legacy artifact note: @asyncapi/* packages
  • Legacy artifact note: @posthog/* packages
  • Legacy artifact note: @postman/* packages
  • Legacy artifact note: @voiceflow/* packages
  • Legacy artifact note: @accordproject/* packages
  • Legacy artifact note: @browserbasehq/* packages
  • Legacy artifact note: @actbase/* packages
  • Legacy artifact note: @oku-ui/* packages
  • Legacy artifact note: @mcp-use/* packages

Incidents in this campaign

  1. ENS npm packages hit by Shai-Hulud
  2. Zapier npm packages hit by Shai-Hulud

Appendix · Affected packages

@ensdomains 2025-11-23 to 2025-11-24
1.1.5
@ensdomains 2025-11-23 to 2025-11-24
1.0.1
@ensdomains 2025-11-23 to 2025-11-24
0.1.2
@ensdomains 2025-11-23 to 2025-11-24
0.0.4
@ensdomains 2025-11-23 to 2025-11-24
0.1.1
@ensdomains 2025-11-23 to 2025-11-24
0.0.7
@ensdomains 2025-11-23 to 2025-11-24
0.0.4
@ensdomains 2025-11-23 to 2025-11-24
3.0.1
@ensdomains 2025-11-23 to 2025-11-24
1.0.1
@ensdomains 2025-11-23 to 2025-11-24
1.2.1
@ensdomains 2025-11-23 to 2025-11-24
0.5.3
@ensdomains 2025-11-23 to 2025-11-24
0.0.2
50 more packages
@ensdomains 2025-11-23 to 2025-11-24
0.2.9
@ensdomains 2025-11-23 to 2025-11-24
0.1.2
@ensdomains 2025-11-23 to 2025-11-24
0.0.2
@ensdomains 2025-11-23 to 2025-11-24
0.0.3
@ensdomains 2025-11-23 to 2025-11-24
1.0.4
@ensdomains 2025-11-23 to 2025-11-24
1.6.1
@ensdomains 2025-11-23 to 2025-11-24
1.0.2
@ensdomains 2025-11-23 to 2025-11-24
0.1.1
@ensdomains 2025-11-23 to 2025-11-24
4.0.3
@ensdomains 2025-11-23 to 2025-11-24
0.0.5
@ensdomains 2025-11-23 to 2025-11-24
2.0.16
@ensdomains 2025-11-23 to 2025-11-24
1.0.5
@ensdomains 2025-11-23 to 2025-11-24
0.1.15
@ensdomains 2025-11-23 to 2025-11-24
0.0.6
@ensdomains 2025-11-23 to 2025-11-24
2.1.52
@ensdomains 2025-11-23 to 2025-11-24
1.0.1
@ensdomains 2025-11-23 to 2025-11-24
0.2.2
@ensdomains 2025-11-23 to 2025-11-24
0.0.2
@ensdomains 2025-11-23 to 2025-11-24
0.0.32
@ensdomains 2025-11-23 to 2025-11-24
0.0.13
@ensdomains 2025-11-23 to 2025-11-24
0.1.10
@ensdomains 2025-11-23 to 2025-11-24
1.0.1
@ensdomains 2025-11-23 to 2025-11-24
0.0.2
@ensdomains 2025-11-23 to 2025-11-24
0.0.4
@ensdomains 2025-11-23 to 2025-11-24
0.2.4
@ensdomains 2025-11-23 to 2025-11-24
1.3.1
@ensdomains 2025-11-23 to 2025-11-24
0.6.51
@ensdomains 2025-11-23 to 2025-11-24
3.4.6
@ensdomains 2025-11-23 to 2025-11-24
0.1.1
@ensdomains 2025-11-23 to 2025-11-24
0.0.3
@ensdomains 2025-11-23 to 2025-11-24
4.0.4
@ensdomains 2025-11-23 to 2025-11-24
1.10.2
ethereum-ens 2025-11-23 to 2025-11-24
0.8.1
@zapier 2025-11-23 to 2025-11-24
0.1.180.1.190.1.20
@zapier 2025-11-23 to 2025-11-24
0.1.120.1.130.1.14
@zapier 2025-11-23 to 2025-11-24
6.4.16.4.26.4.3
@zapier 2025-11-23 to 2025-11-24
1.0.31.0.41.0.5
@zapier 2025-11-23 to 2025-11-24
11.0.311.0.411.0.5
@zapier 2025-11-23 to 2025-11-24
3.0.13.0.23.0.3
@zapier 2025-11-23 to 2025-11-24
1.1.31.1.41.1.5
@zapier 2025-11-23 to 2025-11-24
1.9.11.9.21.9.3
@zapier 2025-11-23 to 2025-11-24
0.1.20.1.30.1.4
@zapier 2025-11-23 to 2025-11-24
0.15.50.15.60.15.7
zapier-async-storage 2025-11-23 to 2025-11-24
1.0.11.0.21.0.3
redux-router-kit 2025-11-23 to 2025-11-24
1.2.21.2.31.2.4
zapier-platform-cli 2025-11-23 to 2025-11-24
18.0.218.0.318.0.4
zapier-platform-core 2025-11-23 to 2025-11-24
18.0.218.0.318.0.4
zapier-platform-legacy-scripting-runner 2025-11-23 to 2025-11-24
4.0.24.0.34.0.4
zapier-platform-schema 2025-11-23 to 2025-11-24
18.0.218.0.318.0.4
zapier-scripts 2025-11-23 to 2025-11-24
7.8.37.8.4

Samples and hashes sit on each incident page, linked above

References

  1. Sha1-Hulud the Second Comingstepsecurity.io
  2. Sha1-Hulud the Second Coming Affected Package Liststepsecurity-public-media.s3.us-west-2.amazonaws.com

Source record: oss/campaigns/sha1-hulud-npm-packages/meta.yaml