Malware & Info-Stealers 2025 Incident #44 CVE-2025-59037

Shai-Hulud npm worm

Estimated Financial Impact
$10-50M+; ~27% of cloud environments
Blast Radius
Self-replicating; 700+ packages; CISA advisory

What Happened

The Shai-Hulud self-replicating npm worm originated from the chalk/debug phishing attack and expanded in scope. It harvested GitHub PATs, npm tokens, and AWS/GCP/Azure keys, then used stolen tokens to automatically infect other packages. The second wave compromised 700+ packages and 25,000+ repos. The malware included a destructive failsafe: if it lost C2 access, it would attempt to destroy the user's home directory.

Sources: JFrog analysis · CISA alert

✓

Risk Guard: Caught

PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS; SOURCE_SINGLE_CONTRIBUTOR pre-existing on many compromised packages

Risk Guard Check Codes That Flag This Incident

PACKAGE_ACTIVE_MALWAREPACKAGE_INSTALL_SCRIPTSSOURCE_SINGLE_CONTRIBUTOR

How Every Tool Performed

2 Caught 1 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS; SOURCE_SINGLE_CONTRIBUTOR pre-existing on many compromised packages
Sonatype (Nexus) Partial Limited ecosystem coverage for this attack
Socket Caught Behavioral analysis detects malicious payload.
Snyk Missed No malware detection capability
Black Duck Missed No malware detection capability
Endor Labs Missed No malware detection capability
← RubyGems mass typosquatting Nx / s1ngularity →