Shai-Hulud npm worm ran code just by opening a folder
In August 2026 an attacker gained access to the GitHub account of a maintainer of popular npm caching libraries and pushed malicious versions with valid signatures through the legitimate release pipeline. Within four hours the payload spread to hundreds of packages, executing via editor and AI-agent config files like .vscode/tasks.json and .claude/settings.json when a folder was opened.
- Infection spread via .vscode/tasks.json and .claude/settings.json on folder open
- Malicious versions carried valid provenance signatures from the release pipeline
- In four hours the worm spread to hundreds of npm packages
- The worm collected npm, GitHub, cloud and Kubernetes tokens to spread further
Read next
Security