Bitsea Logo
  • About us
  • Services
  • Resources
  • Contact
  • Career
Bitsea Logo

Shai-Hulud, npm, and modern software supply chains

27.01.2026

Dr. Andreas Kotulla

Open source security

In September 2025, the npm ecosystem experienced one of the most consequential software supply-chain compromises to date. A self-propagating worm, now commonly referred to as Shai-Hulud, compromised hundreds of npm packages, harvested developer and CI/CD credentials, and used those credentials to spread laterally across the ecosystem by publishing further malicious updates under the identities of legitimate maintainers. Within weeks, a

Read more
  • Privacy Policy
  • Imprint
  • German

Copyright 2026 Bitsea GmbH

About us

  • Vision
  • Timeline
  • Tisax
  • Associations
  • Partners
  • Sustainability

Services and Solutions

  • CRA Guardian
  • Open-Source-Management
  • Software Quality Analysis

Resources

  • Research
  • Webinars
  • Blog & Community
  • Events
  • Lexicon
  • Datasheets

Career

  • Jobs

Contact Us

+49 (0) 2241 8942615
info@bitsea.de
Request a demo

  • About us
    • About us
    • Vision
    • Timeline
    • Tisax
    • Associations
    • Partners
    • Sustainability
  • Services
    • Services
    • Open-Source-Management
    • Software Quality Analysis
    • Technical Project Management
  • Resources
    • Resources
    • Research
    • Webinars
    • Events
    • Blog & Community
    • Lexicon
  • Contact
  • Career
    • Career
    • Life at Bitsea