ActiveSpans 3 functions & 3 industries
Updated

GitHub & npm Under Siege: Megalodon, Shai-Hulud, and Wormable Malware Redefine Supply Chain Risk

Trusted build systems are becoming the attack surface, letting malware spread through normal software delivery.

What is this trend?

Automation-heavy software pipelines are being turned into propagation channels, where stolen tokens, poisoned workflows, and trusted package updates let attackers scale compromise across the open-source ecosystem.

  • CI/CD trust is the target: attackers abuse normal build and release paths instead of breaking them outright.
  • Token theft and workflow abuse let malware move from one repo to many, fast.
  • Signed or legitimate-looking updates can still carry malicious payloads when provenance is weak.
  • Open-source package ecosystems now amplify a single compromise into downstream supply-chain risk.
  • Defenders need tighter pipeline controls, secret handling, and stronger provenance checks.

What’s the latest?

AI-powered npm supply chain attacks like SANDWORM_MODE are exploiting coding assistants and CI/CD pipelines to steal developer secrets and deploy undetectable, multi-stage malware—exposing critical bl

How it developed earlier updates

  1. A coordinated wave of supply chain attacks—led by Megalodon and Shai-Hulud—has shattered trust in open-source automation, hijacking thousands of GitHub repos and npm packages with stealthy, wormable m

    GitHub & npm Under Siege: Megalodon, Shai-Hulud, and Wormable Malware Redefine Supply Chain Risk
  2. Massive audits reveal that even top repositories are riddled with misconfigurations, turning trusted automation into prime targets for supply chain attacks.

    ‘Cordyceps’ Exploit Exposes Crumbling Trust in GitHub Actions, Sparking CI/CD Security Reckoning

Where this is playing out

Related trends

Stay ahead of what’s changing

Get the weekly brief and deep-dive reporting in your inbox.