How to Detect Leaked Cloud Credentials From Developer Packages
Retrospective: this article looks back at events from September 2025, written in 2026 with the benefit of hindsight.
Supply-chain worms like Shai-Hulud steal cloud credentials from developer machines and CI runners. Here is how to detect leaked credentials and respond quickly.
Step 1: Use provider leak detection
- GitHub secret scanning (including push protection and partner program alerts) detects secrets in repositories — and, through the partner program, notifies cloud providers like AWS and Microsoft when their credentials appear in public repositories.
- AWS may notify you and apply the
AWSCompromisedKeyQuarantineV2(or later) managed policy to exposed keys. - Microsoft Entra ID Protection includes leaked credentials detection for user passwords (with password hash sync) and can flag leaked service principal credentials.
Make sure those notifications reach a monitored mailbox.
Step 2: Search public repositories for your organization
Monitor GitHub for new public repositories created under employee accounts, especially with suspicious names. Shai-Hulud created repositories to publish stolen secrets.
Step 3: Scan developer environments
Use EDR on developer machines and CI runners. After an ecosystem incident, check for known malicious package versions in lockfiles and caches.
Step 4: Rotate exposed credentials
For any credential possibly exposed:
- Rotate or revoke immediately (cloud keys, npm/GitHub tokens, service principal secrets).
- Review activity using the credential in CloudTrail, Azure activity logs and Entra sign-in logs.
- Remove attacker-created resources.
Step 5: Reduce what's available to steal
- Developers use IAM Identity Center and Azure CLI with Entra sign-in — short-lived tokens instead of static keys.
- CI uses OIDC federation.
- Disable npm install scripts where possible (
--ignore-scripts) and use lockfiles.
Verify
Count long-lived cloud credentials on developer machines (target: zero) and confirm leak notifications route to responders.
- Shai-Hulud (Sept 2025): A Self-Spreading npm Worm That Steals Cloud Secrets Incident Teardowns
- Detecting npm Supply Chain Worm: Sentinel and GuardDuty Detections Detection & Response
- CIO Brief: Open-Source Worms and Your Cloud Keys CIO Briefings