chiprook
← Security
SecuritySeptember 21, 2026, 01:00

Shai-Hulud npm worm ran code just by opening a folder

In August 2026 an attacker gained access to the GitHub account of a maintainer of popular npm caching libraries and pushed malicious versions with valid signatures through the legitimate release pipeline. Within four hours the payload spread to hundreds of packages, executing via editor and AI-agent config files like .vscode/tasks.json and .claude/settings.json when a folder was opened.

Shai-Hulud npm worm ran code just by opening a folder
#Npm#GitHub#VSCode#Claude
Read next
Security

Cyberattacks Hit OT Systems at Two Colorado Water Utilities

Security

Siemba brings continuous IDOR testing to production APIs

Security

CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog

Security

Revolut Customers Hit by Phishing Wave After Data Breach