Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Singapore’s Cyber Security Agency (CSA) reported that more than 180 npm packages had been compromised in the Shai-Hulud supply-chain attack as of September 23, 2025. The campaign involved a malicious self-propagating payload and credential theft, and the CSA identified @ctrl/tinycolor as the starting compromise. The 180+ figure is a dated report, not a current inventory of affected packages.

What happened in the Shai-Hulud npm attack?

In an alert dated September 23, 2025, the CSA described an ongoing supply-chain attack involving npm packages. It said researchers had identified a malicious payload designed to spread to other packages, and reported that more than 180 packages had been compromised by that date. The CSA named @ctrl/tinycolor as the starting compromise. Read the CSA alert.

The campaign’s high-level pattern was credential theft coupled with self-propagation: compromised credentials and the payload enabled further package compromise. The cited alert does not establish a complete credential list or a package-by-package inventory with affected versions, so neither should be inferred from the headline count.

Why can a compromised npm package affect a project?

npm is the default package manager for Node.js and provides reusable software modules. A project may depend on a package directly, or receive it indirectly as a transitive dependency of another package. As a result, a development team could be exposed even if it did not knowingly add the compromised package to its own dependency list.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

Whether a particular project was exposed depends on the package and version it resolved and whether that version was installed. The CSA’s dated total alone cannot answer those project-specific questions.

What should developers do if their project may be affected?

Use an incident-specific package-and-version list from a reliable source, then compare it with your project’s dependency and installation history. The CSA’s September 2025 alert supplies the campaign context and dated count, but the materials cited here do not provide a current, complete affected-version inventory. Do not treat the package name alone or the 180+ figure as sufficient to determine exposure.

  1. Check exposure. Review direct and transitive dependencies and installation history against a verified list of affected package versions. Include the environments where those versions may have been installed.
  2. Remove affected versions. If the comparison confirms an affected version, remove it and resolve to a version confirmed safe by a reliable incident-specific source.
  3. Rebuild affected systems. The CSA’s supply-chain response guidance recommends rebuilding systems where malicious packages were installed. Avoid relying on a simple package removal as proof that an environment is clean.
  4. Rotate potentially exposed credentials. Replace credentials that may have been accessible to the compromised environment, and review cloud and source-code environments for unauthorized access.

These response actions follow the CSA’s broader 2026 advisory on securing software supply chains and development workflows. It is general guidance, not a Shai-Hulud-specific package list. Apply it to this incident only after establishing whether an affected version was present.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should the 180+ package figure be read?

It means the CSA reported over 180 compromised npm packages on September 23, 2025. It does not say how many packages are affected now, establish the present status of any package on the registry, or identify every version that was compromised. Later npm supply-chain campaigns are separate incidents; their package lists and counts should not be added to Shai-Hulud’s dated figure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.