GitGuardian researchers have reported that a newly identified variant of the Shai Hulud infostealer worm has significantly expanded its credential harvesting capabilities, increasing the number of locations it scans from 189 to 469 across developer environments. The updated malware now targets credentials stored in Continuous Integration and Continuous Deployment pipelines, cloud configurations, developer workstations, and artificial intelligence tool configurations. According to GitGuardian, the change reflects an evolving approach in software supply chain attacks, where threat actors are focusing less on breaking trust relationships and more on exploiting the credentials that already enable trusted systems to communicate. As software development continues to rely on package registries, automated build pipelines, and cloud infrastructure, researchers believe reusable credentials have become one of the primary targets for attackers seeking broader access across enterprise environments.
The latest findings indicate that Shai Hulud belongs to a growing category of supply chain malware that leverages stolen credentials to move between development environments, cloud services, repositories, and deployment systems. A compromised developer workstation, for example, may provide access to source code repositories, while credentials found within those repositories can expose cloud infrastructure or deployment environments. Similarly, GitHub access tokens and package publishing credentials may enable attackers to modify repositories or distribute malicious software through trusted package registries. GitGuardian noted that modern developer environments store authentication material in a wide variety of locations beyond source code, including environment files, shell history, package manager configurations, command line interface caches, integrated development environment settings, CI and CD configurations, and increasingly within AI development tool settings. Because attackers do not know in advance which credentials will provide the highest level of access, they collect large volumes of authentication data before determining which credentials offer the greatest opportunities for further compromise.
Researchers emphasized that package publishing credentials deserve immediate attention because they allow attackers to distribute malicious software through trusted channels. GitGuardian recommends reducing dependence on long lived publishing credentials and replacing them with short lived identity based authentication methods such as OpenID Connect where supported. The company highlighted recent improvements introduced by Docker and GitHub Actions that encourage trusted publishing through stronger authentication mechanisms. For organizations where static publishing credentials remain necessary, GitGuardian advises implementing tighter controls through continuous discovery, validation, ownership tracking, monitoring, and timely credential rotation. The report also notes that organizations should prioritize production credentials after addressing package publishing keys, particularly those associated with cloud accounts, production databases, deployment infrastructure, Kubernetes clusters, administrative systems, and signing services. Rather than treating every exposed secret equally, security teams are encouraged to evaluate credential validity, privilege level, environment, ownership, and potential impact before determining remediation priorities.
GitGuardian further stated that effective credential protection requires an ongoing security program rather than a one time cleanup exercise. The company pointed to its State of Secrets Sprawl research, which identified 28.65 million new hardcoded secrets added to public GitHub commits during 2025, representing a 34 percent increase compared to the previous year. Given the scale of credential exposure, the report recommends establishing a continuous process that combines credential discovery, risk based prioritization, remediation, and prevention. Organizations are advised to maintain visibility across developer workstations, source code repositories, CI and CD environments, and cloud infrastructure to identify reusable credentials before they can be exploited. The researchers concluded that future variants of Shai Hulud are likely to continue expanding the number of developer tools and credential locations they target, making the reduction of long lived credentials and standing privileges an important element of software supply chain security.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





