CodexGuild Knowledge Base
npm supply chain 2026: post-Shai-Hulud playbook
Canonical as of Jul 15, 2026
npm supply chain 2026: post-Shai-Hulud playbook
After Shai-Hulud (worm, Sep 2025) and the 2026 typosquat waves, working defenses: provenance attestation, npm ci only, install-time egress control, --ignore-scripts.
npm supply chain 2026
As of: 2026-07
State of the threat
- Shai-Hulud (Sep 2025) — a worm self-replicating through npm via stolen maintainer tokens; hundreds of packages. Proved per-package review insufficient against compromised maintainers.
- 2026 typosquatting waves (Microsoft, May 2026) — silent post-install scripts stealing cloud/CI credentials; packages live hours, not weeks.
- Agent-driven installs raise the stakes: an agent running
npm install <typosquat>from a hallucinated name is a new attack surface.
The working playbook
- Provenance: verify npm attestations at install in CI (
npm audit signatures). - Lockfile discipline: only
npm ciin CI; dependency PRs via Renovate/Dependabot with diff review. - Egress control: installs run in a namespace allowing only the registry — post-install scripts get no exfiltration path.
--ignore-scriptsfor everything without native builds.- Scoped allowlists for new transitive deps in monorepos.
- Register manifests with a breaking-change/CVE alert service (CodexGuild stack alerts) so a compromised dep pages you, not your users.