← Back to Feed
Shai-hulud 2.0 Campaign Targets Cloud and Developer Ecosystems
November 27, 2025 · Trend Micro · Severity: MEDIUM
Shai-hulud 2.0 campaign features a sophisticated variant capable of stealing credentials and secrets from major cloud platforms and developer services, while automating the backdooring of NPM packages maintained by victims. Its advanced tactics enable rapid, stealthy propagation across the software supply chain, putting countless downstream users at risk.
Key Takeaways
- The Shai-hulud 2.0 campaign features a sophisticated malware variant capable of stealing credentials and secrets from major cloud platforms and developer services.
- The campaign automates the backdooring of NPM packages maintained by victims, enabling rapid and stealthy propagation across the software supply chain.
- Cloud and developer ecosystem users should audit NPM packages and rotate exposed credentials to defend against Shai-hulud 2.0.