Multi-CloudCIO BriefingsRetrospectives

CIO Brief: Open-Source Worms and Your Cloud Keys

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2025, written in 2026 with the benefit of hindsight.

The short version: In September 2025, a self-spreading worm infected hundreds of open-source software packages. When developers installed them, it stole their cloud keys and passwords, published them publicly, and used stolen accounts to infect more packages automatically.

Why this matters to non-technical leaders

Your developers use thousands of free, open-source components. Installing one runs code on their computer automatically. If a component is infected, it can steal the keys your developers use to access your cloud and products — and spread further.

The business impact

  • Stolen cloud credentials leading to data theft or tampering.
  • Public exposure of secrets.
  • Potential infection of software you publish.

Questions to ask your team

  • Do our developers have long-lived cloud keys on their computers?
  • Do we control which open-source package versions get installed?
  • Would we be notified if our credentials appeared publicly online?
  • Could we rotate all developer and pipeline credentials within a day?

What good looks like

Developers using short-lived cloud access, locked dependency versions, monitoring for leaked credentials, protected developer accounts on code platforms, and a practiced rotation plan.

The decision

Ask engineering to eliminate long-lived cloud keys from developer machines. It's the single change that most limits the damage from this kind of attack.

shai-hulud npm worm impactShai-Hulud npm worm2025

More on this story