GitHub & npm Under Siege: Megalodon, Shai-Hulud, and Wormable Malware Redefine Supply Chain Risk
Trusted build systems are becoming the attack surface, letting malware spread through normal software delivery.
What is this trend?
Automation-heavy software pipelines are being turned into propagation channels, where stolen tokens, poisoned workflows, and trusted package updates let attackers scale compromise across the open-source ecosystem.
- CI/CD trust is the target: attackers abuse normal build and release paths instead of breaking them outright.
- Token theft and workflow abuse let malware move from one repo to many, fast.
- Signed or legitimate-looking updates can still carry malicious payloads when provenance is weak.
- Open-source package ecosystems now amplify a single compromise into downstream supply-chain risk.
- Defenders need tighter pipeline controls, secret handling, and stronger provenance checks.
What’s the latest?
AI-powered npm supply chain attacks like SANDWORM_MODE are exploiting coding assistants and CI/CD pipelines to steal developer secrets and deploy undetectable, multi-stage malware—exposing critical bl
How it developed earlier updates
A coordinated wave of supply chain attacks—led by Megalodon and Shai-Hulud—has shattered trust in open-source automation, hijacking thousands of GitHub repos and npm packages with stealthy, wormable m
GitHub & npm Under Siege: Megalodon, Shai-Hulud, and Wormable Malware Redefine Supply Chain RiskMassive audits reveal that even top repositories are riddled with misconfigurations, turning trusted automation into prime targets for supply chain attacks.
‘Cordyceps’ Exploit Exposes Crumbling Trust in GitHub Actions, Sparking CI/CD Security Reckoning