GitLab discovers widespread npm supply chain attack

257 · · Nov. 24, 2025, 11:42 p.m.
Summary
GitLab's Vulnerability Research team uncovered a large-scale npm supply chain attack featuring a sophisticated malware called 'Shai-Hulud.' This malware can harvest credentials, propagate through npm packages, and includes a destructive payload that can delete user data if its access is severed. GitLab validated that they were not affected and aims to assist the wider community with their findings on how to respond to such threats.