Shai-Hulud was the best thing to happen to supply chain security
aikido.dev | blog | #supply-chain | #npm | #aikido | #shai-hulud | #software-supply-chain | #trusted-publishing | #oidc
Summary
Aikido's data shows npm Trusted Publishing adoption jumped from roughly 20-50 packages a week to 430 after the 2025 attack wave (S1ngularity, the Debug/Chalk phishing, and the self-replicating Shai-Hulud worm that compromised 700+ packages), though only 25% of top-package download volume is covered yet.
Why it matters
This coverage gives security teams current context for monitoring, validation, and remediation.
- Published
- Collected
Skip to content