Multi-CloudDetection & ResponseRetrospectives

Detecting npm Supply Chain Worm: Sentinel and GuardDuty Detections

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2025, written in 2026 with the benefit of hindsight.

Package ecosystem worms leave signals across developer endpoints, code platforms and cloud logs. These detections help spot an infection and its use of stolen credentials.

Signals worth watching

  • npm install processes spawning tools like TruffleHog or making unusual outbound connections.
  • New public GitHub repositories created by employee accounts with unusual names (for example, referencing the worm or "migration").
  • Unexpected package publishes from your organization's npm accounts.
  • Cloud credentials used from unfamiliar IPs shortly after developer installs.
  • GitHub secret scanning or cloud provider leak notifications.

Where the data lives

  • EDR on developer machines and self-hosted runners (process and network events).
  • GitHub audit log (repository creation, visibility changes, token use).
  • npm audit logs for publishing.
  • CloudTrail, Azure Activity and Entra ID logs for credential use.

A starting query

Node.js or npm processes spawning secret-scanning tools or suspicious shells:

DeviceProcessEvents
| where InitiatingProcessFileName in~ ("node", "node.exe", "npm", "npm.cmd")
| where FileName has_any ("trufflehog", "curl", "wget", "bash", "sh", "powershell")
| project Timestamp, DeviceName, AccountName, InitiatingProcessCommandLine, ProcessCommandLine

Expect noise from legitimate build scripts; tune by known project paths.

Response

  1. Isolate affected machines and runners.
  2. Remove malicious package versions and clear caches.
  3. Rotate all credentials present on affected systems.
  4. Delete attacker-created public repositories and check for unauthorized package publishes.
detect npm supply chain wormShai-Hulud npm worm2025

More on this story