people · May 20, 2026
Sonatype Security Research Team Reports New Shai-Hulud npm Package Attack
Share the canonical public link.
Sonatype Security Research Team published details on the return of the Shai-Hulud campaign on May 19, 2026. The attack compromised trusted npm packages using install-time hooks to steal developer and CI/CD secrets before spreading via publishing access. Ilkka Turunen, Sonatype’s Field CTO, stated malicious code executes on install. Sonatype Guide helps teams assess exposure and rotate compromised credentials following the prior attack tracked as sonatype-2026-003200.
Below validation threshold — auto-passed without scoring