Shai-Hulud compromised a dev machine and raided GitHub org access: a post-mortem
trigger.dev·1d·
Discuss: Hacker News
🔓Hacking
Preview
Report Post

On November 25th, 2025, we were on a routine Slack huddle debugging a production issue when we noticed something strange: a PR in one of our internal repos was suddenly closed, showed zero changes, and had a single commit from... Linus Torvalds?

The commit message was just "init."

Within seconds, our #git Slack channel exploded with notifications. Dozens of force-pushes. PRs closing across multiple repositories. All attributed to one of our engineers.

Nick’s initial alert

We had been compromised by Shai-Hulud 2.0, a sophisticated npm supply chain worm that compromised over 500 packages, affected 25,000+ repositories, and spread across the Ja…

Similar Posts

Loading similar posts...