Shai-Hulud: What to Know About the Malware Spreading Through Software Pipelines
In briefShai-Hulud malware has been linked to roughly 300 npm and PyPI package entries.OpenAI, Microsoft, and Mistral AI disclosed recent Shai-Hulud-related incidents.The malware abused GitHub Actions and trusted software publishing workflows. A malware campaign known as “Shai-Hulud” is spreading through the software pipelines developers use to build and distribute code, raising new concerns about how much of the modern internet now depends on automated systems operating with little direct human oversight. Researchers linked the Shai-Hulud malware campaign to roughly 320 package entries across Node Package Manager (NPM) and PyPI, two of the largest online repositories developers use to download and share JavaScript and Python software packages. The affected packages collectively account for more than 518 million monthly downloads. “Shai-Hulud is significant because it exposes a problem we cannot fully patch away: modern software is built by running other people‘s code,” Jeff Williams, CTO of California-based security firm Contrast Security, told Decrypt. “Developers do not merely ’download libraries. They install them, build with them, test with them, deploy with them, and eventually execute them. And if you run a malicious library, it can do almost anything you can do.” Advances in artificial intelligence complicate the threat, Williams said, comparing Shai-Hulud to making a computer a