Detecting npm Supply Chain Worm: Sentinel and GuardDuty Detections
Retrospective: this article looks back at events from September 2025, written in 2026 with the benefit of hindsight.
Package ecosystem worms leave signals across developer endpoints, code platforms and cloud logs. These detections help spot an infection and its use of stolen credentials.
Signals worth watching
- npm install processes spawning tools like TruffleHog or making unusual outbound connections.
- New public GitHub repositories created by employee accounts with unusual names (for example, referencing the worm or "migration").
- Unexpected package publishes from your organization's npm accounts.
- Cloud credentials used from unfamiliar IPs shortly after developer installs.
- GitHub secret scanning or cloud provider leak notifications.
Where the data lives
- EDR on developer machines and self-hosted runners (process and network events).
- GitHub audit log (repository creation, visibility changes, token use).
- npm audit logs for publishing.
- CloudTrail, Azure Activity and Entra ID logs for credential use.
A starting query
Node.js or npm processes spawning secret-scanning tools or suspicious shells:
DeviceProcessEvents
| where InitiatingProcessFileName in~ ("node", "node.exe", "npm", "npm.cmd")
| where FileName has_any ("trufflehog", "curl", "wget", "bash", "sh", "powershell")
| project Timestamp, DeviceName, AccountName, InitiatingProcessCommandLine, ProcessCommandLine
Expect noise from legitimate build scripts; tune by known project paths.
Response
- Isolate affected machines and runners.
- Remove malicious package versions and clear caches.
- Rotate all credentials present on affected systems.
- Delete attacker-created public repositories and check for unauthorized package publishes.
- Shai-Hulud (Sept 2025): A Self-Spreading npm Worm That Steals Cloud Secrets Incident Teardowns
- How to Detect Leaked Cloud Credentials From Developer Packages How-To & Hardening
- CIO Brief: Open-Source Worms and Your Cloud Keys CIO Briefings