Attackers Testing New Strain of Shai-Hulud on npm: Aikido

Published: (January 5, 2026 at 10:16 AM EST)
1 min read
Source: DevOps.com

Source: DevOps.com

New Strain of Shai‑Hulud Observed in npm Packages

Threat actors behind the virulent Shai-Hulud worm that wreaked havoc in open npm repositories toward the end of 2025 apparently are trying out a new strain that comes with slight modifications. Security researchers with Aikido Security, who have been tracking Shai-Hulud for months, wrote in a report…

Back to Blog

Related posts

Read more »

Yes, We Know AI Isn’t a Person

Let’s get the obvious out of the way right up front. AI isn’t a person. Thank you, Captain Obvious. We’re all on the same page. And yet, when we announced that...