Back to advisories

Happy Birthday, Shai-Hulud

The Shai-Hulud supply chain worm has been active for one year, targeting npm packages like @ctrl/tinycolor to harvest credentials and self-propagate across development environments. The threat has evolved to exploit OIDC tokens and continues spreading through multiple waves. Any organization using compromised npm dependencies faces credential theft and potential lateral movement into their infrastructure.

CRITICALAdvisorySep 20, 2026
Action required
Audit all npm package dependencies for @ctrl/tinycolor and known compromised packages. Rotate all developer credentials, API tokens, and OIDC tokens immediately. Scan package-lock.json files across all repos for malicious versions and block installation of flagged packages at your npm proxy.
Affected products
@ctrl/tinycolorTruffleHogCrowdStrikenpmGitHub