How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Shai-Hulud Returns: The npm Worm That Only Works Because Your Secrets Are Standing Still

calendar_today August 9, 2026 person Developer AXE-WEB domain akeyless

The recent Shai-Hulud supply chain attack demonstrates a fundamental shift in how attackers compromise organizations. Rather than exploiting software vulnerabilities, the malware targets what already exists on developer workstations and CI/CD systems: long-lived credentials. From .env files and cloud credentials to HashiCorp Vault tokens and AI coding assistants, the attack succeeds because secrets remain static, discoverable, and reusable.

open_in_new Read original post