BrokeIt - Trending Repos · All episodes: ↗

Six Million Fake Stars, npm v12 Blocks Install Scripts, Shai-Hulud Strikes Again

2026-07-23 · 7 min

Listen · Apple Podcasts Listen · Spotify

Stories covered

Transcript

Intro

Sam: Four separate supply-chain attacks on npm and PyPI in six weeks. Same target every time — the credentials sitting in your build pipeline.

Kai: [excited] And one of them's a brand-new Shai-Hulud worm variant! I'm Kai.

Sam: [dry] And I'm Sam. I read the postmortems so you don't have to.

Kai: It's July 23rd, 2026, and we've got three stories that are basically screaming at your dependency tree.

Sam: Let's get into it.

Kai: First up — Shai-Hulud is back, and it brought friends. Four supply-chain campaigns hit npm and PyPI in one stretch.

Sam: Then npm v12 ships this month and finally kills install scripts by default — the thing that made all those worms possible.

Kai: [excited] And six MILLION suspected fake stars on GitHub. Your trending page is lying to you.

Sam: [dry] I've been saying that on this show for a year, but sure, now there's a paper.

Shai-Hulud strikes again: four more supply-chain attacks hit npm and PyPI

Kai: So GitGuardian tallied it up — between early June and July 14th, four distinct campaigns hit the registries.

Sam: Four different entry points, though. That's the part that keeps me up at night. This wasn't one crew hitting refresh.

Kai: Right — a new Shai-Hulud worm variant, typosquatted payment SDKs, a stolen publishing token, and a hijacked CI pipeline.

Sam: And they all end up in the same place: harvesting credentials out of developer environments and build servers.

Kai: The worm part is what freaks me out. It self-propagates — infects a package, steals the maintainer's token, then publishes to their OTHER packages.

Sam: That's the definition of a worm, Kai. It doesn't need a human after patient zero.

Kai: [beat] Okay, but the typosquatted payment SDKs — those are just evil. People installing what they think is a Stripe helper?

Sam: Oldest trick in the book, and it STILL works, because nobody reads the package name carefully at 2am.

Kai: Hot take: registries need mandatory 2FA on publish, no exceptions, or this never stops.

Sam: [foul] Half of these had 2FA. The stolen publishing token bypassed it entirely — a token IS the second factor, and it walked right out the door.

Kai: Ouch. Okay, fair.

Sam: The scary word here is 'streak.' Registry compromise is routine now. It's a Tuesday.

Kai: So for you: pin your dependencies, use lockfiles, scan for leaked secrets in CI.

Sam: And rotate any publishing token you haven't looked at since 2025. Assume it's already in someone's collection.

npm v12 ships this month, blocking dependency install scripts by default

Kai: Story two — and this is the fix I've been begging for! npm v12 ships this month and stops running dependency install scripts by default.

Sam: [dry] Kai, that was not a funding round.

Kai: [laughs] To ME it's worth billions in saved incident response!

Sam: Alright, it's genuinely good. Preinstall, install, postinstall — those hooks were the entry point behind a year of worm attacks.

Kai: Malicious package lands, npm auto-runs its postinstall, and boom — code execution before you've even imported anything.

Sam: Closing that by default is the single biggest thing they could do. Credit where it's due.

Kai: Wait — you're complimenting a change? Someone screenshot this.

Sam: [dry] Don't get used to it. Because this is ALSO going to break a lot of CI on July 31st.

Kai: Yeah — native modules like bcrypt and better-sqlite3 need those build steps to compile.

Sam: So you can't just flip it on and walk away. You need an approve-scripts allowlist for the packages that legitimately need it.

Kai: And if you're on 11.15 or 11.16, you can prep NOW with the --allow-git and --allow-remote flags before v12 lands.

Sam: Do it in a branch. Run your full build. Find out what breaks on your terms — not at 5pm on a Friday when a deploy fails.

Kai: Hot take: this should've been the default back in like 2019.

Sam: No argument. Better late than another Shai-Hulud.

Kai: For you: audit your postinstall dependencies this week and build that allowlist before the release drops.

'Six Million (Suspected) Fake Stars on GitHub' — research and open analysis fuel fake-star vetting

Kai: Last one — six million suspected fake stars on GitHub. SIX million.

Sam: This is the ICSE 2026 study, using a tool called StarScout. And the number's surged since 2024.

Kai: [excited] See, this is why I love a good trending page — wait, no, this is the opposite of that.

Sam: [laughs] Kai the hype-chaser, having a crisis in real time.

Kai: Because I STAR everything! How do I know what's real anymore?

Sam: The study found the fake accounts have trivial activity — created, star a repo, do nothing else. Ghost accounts.

Kai: And what were they boosting? Please tell me it's cool projects.

Sam: [dry] Mostly short-lived phishing, spam, and malware repos. The stars are a promo campaign for a scam.

Kai: Oh, that's grim. So a repo shoots to 5,000 stars overnight and it's just... bait.

Sam: Which is exactly why I never trust a star spike. There's a companion community gist tracking specific repos with suspected inflation.

Kai: Hot take — GitHub trending is basically unusable as a discovery tool now?

Sam: I wouldn't go that far, but a raw star count means almost nothing. Look at the velocity and WHO's starring.

Kai: For you: before you npm install the hot new repo, check the commit history, the real issues, the actual contributors.

Sam: And if it's 8,000 stars with two commits and no issues? [beat] That's not a project, that's a trap.

Sam: So — four supply-chain campaigns hit npm and PyPI, all hunting your build credentials.

Kai: npm v12 finally blocks install scripts by default this month — prep your allowlist so CI doesn't blow up.

Sam: And six million fake stars on GitHub, mostly promoting scams. Trust nothing shiny.

Kai: Before we go — I looked it up, 'Shai-Hulud' is the giant sandworm from Dune.

Sam: [dry] Of course it is. Attackers naming their worm after a worm. Points for honesty.

Kai: [laughs] Nothing says 'we're coming for your dependency tree' like a thousand-foot desert monster.

Kai: That's the show! Go build your approve-scripts allowlist tonight, and star responsibly.

Sam: [dry] Star responsibly — or don't star at all. See you tomorrow.

This show is made with AI: the hosts’ voices are synthetic and the scripts are AI-assisted. Every story links to its original source.