Cloud Detection & Response
Popular
Highlights
CDR
GitHub
Kubernetes
The Shai-Hulud 2.0 npm Worm: What Happened & How Stream Detected It
Shai-Hulud 2.0 is rapidly backdooring npm packages, spawning tens of thousands of malicious repos, and stealing developer creds. In this blog, we detonate an infected package and show how Stream Security instantly detects and investigates the threat with behavioral analytics + AI Triage (with real Stream platform images included).
.png)
Petr Zuzanov
Nov 27, 2025
5
min
.png)
.png)


.png)






.png)
.png)



