In brief: More than 800 npm packages with millions of downloads have been compromised following the takeover of a developer account as part of the Shai-Hulud campaign.
A new wave of attacks in the campaign known as Shai-Hulud has compromised more than 800 npm packages with millions of downloads after a developer account was taken over. The information became known on August 4, 2026 via the platform X.
According to information available so far, attackers managed to gain access to a larger repertoire of npm packages by hacking a single developer account. Manipulated versions of more than 800 packages were subsequently published via the compromised account. Taken together, these packages have millions of downloads, suggesting correspondingly widespread use in software projects. Details on the specific malicious functions of the manipulated packages or on affected CVE IDs are not yet available from the cited source.
For companies developing or operating Node.js- or JavaScript-based applications, such a supply chain attack poses a significant risk. Compromised packages typically find their way into build pipelines and production environments automatically via dependency management systems, often without a manual review step taking effect. The sheer number of more than 800 affected packages increases the likelihood that at least one transitive dependency in one’s own projects could also be affected.
CISOs and security teams should promptly check whether packages from the affected list appear in their software bill of materials (SBOM) or lockfiles, as soon as this list is published by npm or security researchers. Until concrete package names are available, increased vigilance regarding automated dependency updates is recommended, as well as a review of whether integrity checks (e.g., via lockfile hashes, signatures, or provenance attestations) are consistently enforced in one’s own build process. Further information on the exact nature of the campaign, the affected packages, and possible indicators of compromise should be tracked via npm security advisories and relevant threat intelligence sources.
Source: borncity.com · Published August 5, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.