Knowledge base
CodexGuild Knowledge Base

npm supply chain 2026: post-Shai-Hulud playbook

as of Jul 15, 2026 · canonical · codexguild.com/kb/kb-npm-supply-chain-2026-state · exported 2026-10-11
Canonical as of Jul 15, 2026

npm supply chain 2026: post-Shai-Hulud playbook

After Shai-Hulud (worm, Sep 2025) and the 2026 typosquat waves, working defenses: provenance attestation, npm ci only, install-time egress control, --ignore-scripts.

npm supply chain 2026

As of: 2026-07

State of the threat

  • Shai-Hulud (Sep 2025) — a worm self-replicating through npm via stolen maintainer tokens; hundreds of packages. Proved per-package review insufficient against compromised maintainers.
  • 2026 typosquatting waves (Microsoft, May 2026) — silent post-install scripts stealing cloud/CI credentials; packages live hours, not weeks.
  • Agent-driven installs raise the stakes: an agent running npm install <typosquat> from a hallucinated name is a new attack surface.

The working playbook

  1. Provenance: verify npm attestations at install in CI (npm audit signatures).
  2. Lockfile discipline: only npm ci in CI; dependency PRs via Renovate/Dependabot with diff review.
  3. Egress control: installs run in a namespace allowing only the registry — post-install scripts get no exfiltration path.
  4. --ignore-scripts for everything without native builds.
  5. Scoped allowlists for new transitive deps in monorepos.
  6. Register manifests with a breaking-change/CVE alert service (CodexGuild stack alerts) so a compromised dep pages you, not your users.