White Paper
Shai-Hulud 2.0: Defending the Software Supply Chain With Cloud Development Environments
This white paper examines the Shai-Hulud 2.0 supply-chain attack, which weaponized trusted npm packages to execute malicious preinstall scripts on developer workstations. The campaign compromised hundreds of packages and more than 25,000 GitHub repositories while harvesting cloud credentials, GitHub tokens, SSH keys, and CI/CD secrets. Traditional endpoint protection, dependency scanning, and network monitoring failed because the malicious code ran during a trusted development operation and used legitimate GitHub infrastructure. The paper explains how cloud development environments reduce this risk through isolated and ephemeral workspaces, centralized source code, restricted network egress, approved package registries, infrastructure-as-code templates, and short-lived credentials. These c
