ADVERTISEMENT

Microsoft urges users to change passwords, as the Dune-inspired worm hits again

A resurrected and more vicious Shai-Hulud worm is silently tearing through the software supply chain, compromising developers and cloud pipelines at scale.

Microsoft worm
Paulina Okunytė
Paulina Okunytė Senior Journalist
December 11, 2025 2 min read
Shai-Hulud 2.0 attack chain
Shai-Hulud 2.0 attack chain. Source: Microsoft

Why is the attack so effective?

ADVERTISEMENT
Jurgita Lapienyte justinasv Izabele Pukenaite vilius Ernestas Naprys Gintaras Radauskas
Don't miss our latest stories on Google News. Add us as your Preferred Source on Google
Add us as your Preferred Source on Google.

What actions should organizations take?

  • Revoke or rotate any exposed credentials before attackers can reuse them
  • Isolate compromised CI/CD environments to stop further propagation
  • Audit and tighten access permissions on key vaults, pipelines, and developer identities
  • Maintainers of nmp should use trusted publishing instead of tokens
  • Establish two-factor authentication (2FA) for any writes and publishing actions

ADVERTISEMENT