Shai-Hulud npm Supply Chain Attack: Why Secrets Fueled the Worm
The Shai-Hulud npm worm spread to 300+ packages by stealing secrets. Learn why key rotation isn’t enough—and how dynamic identity stops the next attack.
Pieter Kasselman, Heather Howland
September 17, 2025