Sha1-Hulud: The Second Coming – Supply Chain Attack

⚠️ WARNING ⚠️ npm Supply Chain Under Attack – Sha1-Hulud Malware Spreading Fast! If you've run npm install anytime after November 21, 2025, your system may...

Sha1-Hulud: The Second Coming – Supply Chain Attack
Edgars Garsneks
437 views • Nov 28, 2025
Sha1-Hulud: The Second Coming – Supply Chain Attack

About this video

⚠️ WARNING ⚠️
npm Supply Chain Under Attack – Sha1-Hulud Malware Spreading Fast!

If you've run npm install anytime after November 21, 2025, your system may already be compromised.

In this video, we break down the Sha1-Hulud: The Second Coming attack — a massive malware campaign that infected over 600 npm packages, hijacked 25,000+ GitHub repos, and exfiltrated thousands of API keys, SSH tokens, cloud secrets, and GitHub credentials.

Whether you’re a solo dev or running enterprise CI/CD — you need to see this.

⚠️ Stay informed. Stay protected. And don’t ignore this one.

GitLab Blog: https://about.gitlab.com/blog/gitlab-discovers-widespread-npm-supply-chain-attack/

00:00 - What happened?
00:19 - What is Supply Chain Attack?
00:48 - Sha1-Hulud Explained
02:15 - Am I affected?
03:08 - Recommendations
03:40 - Closing words

#npm #javascript #programming #security #softwaredevelopment #supplychain #hacker #malware

Tags and Topics

Browse our collection to discover more content in these categories.

Video Information

Views

437

Likes

8

Duration

3:51

Published

Nov 28, 2025

Related Trending Topics

LIVE TRENDS

Related trending topics. Click any trend to explore more videos.

Trending Now