# Shai-Hulud / Sha1-Hulud - how can I tell whether my NR is affected

**URL:** <https://discourse.nodered.org/t/shai-hulud-sha1-hulud-how-can-i-tell-whether-my-nr-is-affected/99794>\
**Category:** General\
**Tags:** security, supply-chain-attack\
**Created:** [28 November 2025 05:52 UTC](https://discourse.nodered.org/t/shai-hulud-sha1-hulud-how-can-i-tell-whether-my-nr-is-affected/99794 "2025-11-28T05:52:16Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![gregorius](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gregorius/32/73816_2.png) [@gregorius](https://discourse.nodered.org/u/gregorius)\
**Post date:** [28 November 2025 05:52 UTC](https://discourse.nodered.org/t/shai-hulud-sha1-hulud-how-can-i-tell-whether-my-nr-is-affected/99794/1 "2025-11-28T05:52:16Z")

</div>

Hi There,

Is there any test to check whether my NR installation has been affected by this attack?

I was reading the [GitLab](https://about.gitlab.com/blog/gitlab-discovers-widespread-npm-supply-chain-attack/) write up but it doesn't clearly state how to detect an infection.\

Is there something simple shell command that locates affected packages in my NR installation?

cheers!

---

<div class="post-metadata">

**Author:** ![Trying\_to\_learn](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/trying_to_learn/32/28400_2.png) [@Trying\_to\_learn](https://discourse.nodered.org/u/Trying_to_learn)\
**Post date:** [28 November 2025 06:03 UTC](https://discourse.nodered.org/t/shai-hulud-sha1-hulud-how-can-i-tell-whether-my-nr-is-affected/99794/2 "2025-11-28T06:03:25Z")

</div>

Is this clip related?

[![](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/5/9/59e8274ed950055e4211a186d3f60b9ad5a07002.jpeg "The NPM Worm Is Back - Threat Wire") ](https://www.youtube.com/watch?v=fYzMBowlFtQ)

Or this one?

[![](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/a/7/a7458453cb57bb41e6faccaedd42ab04f220646a.jpeg "the npm malware is a hacking masterpiece") ](https://www.youtube.com/watch?v=lqZo4waMB3c)

---

<div class="post-metadata">

**Author:** ![gregorius](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gregorius/32/73816_2.png) [@gregorius](https://discourse.nodered.org/u/gregorius)\
**Post date:** [28 November 2025 06:14 UTC](https://discourse.nodered.org/t/shai-hulud-sha1-hulud-how-can-i-tell-whether-my-nr-is-affected/99794/3 "2025-11-28T06:14:29Z")

</div>

> [@Trying\_to\_learn](#):
>
> Is this clip related?

> [@gregorius](#):
>
> Is there something simple shell command

is that shell command in either of those clips?

---

<div class="post-metadata">

**Author:** ![Trying\_to\_learn](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/trying_to_learn/32/28400_2.png) [@Trying\_to\_learn](https://discourse.nodered.org/u/Trying_to_learn)\
**Post date:** [28 November 2025 06:19 UTC](https://discourse.nodered.org/t/shai-hulud-sha1-hulud-how-can-i-tell-whether-my-nr-is-affected/99794/4 "2025-11-28T06:19:56Z")

</div>

AFAIK they are just youtube clips talking of the latest NPM problem.

---

<div class="post-metadata">

**Author:** ![gregorius](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gregorius/32/73816_2.png) [@gregorius](https://discourse.nodered.org/u/gregorius)\
**Post date:** [28 November 2025 06:39 UTC](https://discourse.nodered.org/t/shai-hulud-sha1-hulud-how-can-i-tell-whether-my-nr-is-affected/99794/5 "2025-11-28T06:39:19Z")

</div>

OK the gitlab describes some [indicators](https://about.gitlab.com/blog/gitlab-discovers-widespread-npm-supply-chain-attack/#indicators-of-compromise):

```auto
Indicators of compromise

To aid in detection and response, here is a more comprehensive list of the key indicators of compromise (IoCs) identified during our analysis.
Type Indicator Description
file bun_environment.js Malicious post-install script in node_modules directories
directory .truffler-cache/ Hidden directory created in user home for Trufflehog binary storage
directory .truffler-cache/extract/ Temporary directory used for binary extraction
file .truffler-cache/trufflehog Downloaded Trufflehog binary (Linux/Mac)
file .truffler-cache/trufflehog.exe Downloaded Trufflehog binary (Windows)
process del /F /Q /S "%USERPROFILE%*" Windows destructive payload command
process shred -uvz -n 1 Linux/Mac destructive payload command
process cipher /W:%USERPROFILE% Windows secure deletion command in payload
command curl -fsSL https://bun.sh/install | bash Suspicious Bun installation during NPM package install
command powershell -c "irm bun.sh/install.ps1|iex" Windows Bun installation via PowerShell

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [26 February 2026 06:39 UTC](https://discourse.nodered.org/t/shai-hulud-sha1-hulud-how-can-i-tell-whether-my-nr-is-affected/99794/6 "2026-02-26T06:39:34Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
