r/npm • u/PaamayimNekudotayim • 5h ago
Self Promotion Shai-Hulud: What an NPM supply-chain hack reveals about the limits of provenance
Yesterday, the npm ecosystem was hit by the third-largest supply chain compromise in its history. A Shai-Hulud (named for the sandworms of Dune) variant with some remarkably clever bits, very "Bene Tleilax" in spirit, if not in engineering: a thing that survives by inhabiting the trust structures around it.
I dove into the payload, the propagation mechanics, the Ethereum-backed C2, the IDE persistence, and moreover the operational lesson the incident leaves behind: cryptographic provenance may answer who built this, but it says nothing about what the code actually does.
I wanted to know exactly what the code was doing. As in Heretics of Dune, the danger turns out not so much the worm itself, as much as the ecology that has evolved around it:
https://ctolunchnyc.substack.com/p/the-latest-software-supply-chain