CIO Brief: Open-Source Worms and Your Cloud Keys
Retrospective: this article looks back at events from September 2025, written in 2026 with the benefit of hindsight.
The short version: In September 2025, a self-spreading worm infected hundreds of open-source software packages. When developers installed them, it stole their cloud keys and passwords, published them publicly, and used stolen accounts to infect more packages automatically.
Why this matters to non-technical leaders
Your developers use thousands of free, open-source components. Installing one runs code on their computer automatically. If a component is infected, it can steal the keys your developers use to access your cloud and products — and spread further.
The business impact
- Stolen cloud credentials leading to data theft or tampering.
- Public exposure of secrets.
- Potential infection of software you publish.
Questions to ask your team
- Do our developers have long-lived cloud keys on their computers?
- Do we control which open-source package versions get installed?
- Would we be notified if our credentials appeared publicly online?
- Could we rotate all developer and pipeline credentials within a day?
What good looks like
Developers using short-lived cloud access, locked dependency versions, monitoring for leaked credentials, protected developer accounts on code platforms, and a practiced rotation plan.
The decision
Ask engineering to eliminate long-lived cloud keys from developer machines. It's the single change that most limits the damage from this kind of attack.
- Shai-Hulud (Sept 2025): A Self-Spreading npm Worm That Steals Cloud Secrets Incident Teardowns
- How to Detect Leaked Cloud Credentials From Developer Packages How-To & Hardening
- Detecting npm Supply Chain Worm: Sentinel and GuardDuty Detections Detection & Response