# The NPM Worm Is Back - Threat Wire

Source: https://www.youtube.com/watch?v=fYzMBowlFtQ
Recap page: https://rapidrecap.app/video/fYzMBowlFtQ
Generated: 2025-11-26T17:41:18.869+00:00

---
## Quick Overview

Cloudflare experienced a major outage on November 18, 2025, caused by a bug in the bot mitigation service that crashed after a routine configuration change, which resulted in the temporary widespread unavailability of many major internet providers and services. The attacker group Shai Hulud, known for previous supply-chain attacks, was not involved in this incident, despite initial confusion caused by the status page being affected.

**Key Points:**
- Cloudflare experienced a major outage on November 18, 2025, lasting about six hours, with most services restored within three hours.
- The outage was caused by a bug in the bot migration service that crashed following a routine configuration change, not a cyberattack, contrary to initial speculation.
- The bug caused the feature file used by the bot management system to double in size, which then propagated across all machines, leading to degradation of network services.
- The attacker group Shai Hulud, known for supply-chain attacks like the one on NPM packages in August 2023, was not responsible for this specific Cloudflare failure.
- The incident exposed the risk associated with relying heavily on core infrastructure providers, as many major companies, including Zapier, ENS, PostHog, and banks, were affected.
- WatchTower research found that code formatters are unsafe for sharing sensitive data, as they often expose secrets like API keys and database credentials via publicly accessible GitHub repositories, with over 26.3k such repositories exposed.

![Screenshot at 00:12: The on-screen graphic highlights the main topic of the first story segment: "Cloudflare Went Down."](https://ss.rapidrecap.app/screens/fYzMBowlFtQ/00-00-12.png)

**Context:** The video, an episode of Threat Wire hosted by Allie Diamond, discusses two separate but significant cybersecurity incidents. The primary focus is the widespread Cloudflare outage that occurred on November 18, 2025, which disrupted large portions of the internet. The secondary topic addresses the ongoing threat of supply-chain attacks, specifically highlighting the malicious activities of the Shai Hulud group targeting the NPM ecosystem and the general danger of using unvetted online code formatting tools.

## Detailed Analysis

The video covers two main security topics. First, it details the Cloudflare outage on November 18, 2025. Cloudflare's CTO confirmed via Twitter that the issue was not a DNS problem or a cyberattack, but rather a latent bug in the service underpinning bot mitigation capability. This bug crashed after a routine configuration change, causing a broad degradation of network services. The issue lasted about six hours, affecting major providers and services globally. Second, the host pivots to discussing supply-chain risks, referencing the Shai Hulud group that previously compromised NPM packages. This group reportedly became more efficient in their second wave of attacks in November 2023, exploiting vulnerabilities in the AsyncAPI CLI project to steal publishing tokens and leak over 150 million monthly downloads worth of secrets to publicly accessible GitHub repositories described as 'Shai-Hulud: The Second Coming.' Finally, the host warns against using online code formatters, citing research from WatchTower showing that many popular formatters save submitted code, potentially exposing sensitive data like API keys and database credentials, with over 80,000 submissions captured over five years.

### Cloudflare Outage (Nov 18, 2025)

- Outage lasted around six hours, caused by a bug in bot mitigation triggered by a configuration change
- Not a DNS issue or cyberattack
- Affected major services like Zapier, ENS, PostHog, and banks

### Shai Hulud NPM Attacks

- The group used a more efficient attack in November 2023, exploiting a vulnerability in the AsyncAPI CLI project to steal NPM publishing tokens
- Over 150 packages with 132 million monthly downloads were compromised
- Secrets were published to GitHub repos named 'Shai-Hulud: The Second Coming'

### Dangers of Online Code Formatters

- WatchTower found that popular formatters regularly save submitted code, potentially exposing secrets like database credentials and API keys
- Over 80,000 submissions captured over five years from formatters like JSON Formatter and Code Beautify
- URLs for these services are easily searchable

![Screenshot at 00:08: Title card graphic featuring an eagle holding a globe and keyboard, symbolizing internet freedom.](https://ss.rapidrecap.app/screens/fYzMBowlFtQ/00-00-08.png)
![Screenshot at 00:48: Screenshot of the Cloudflare blog post titled "Cloudflare outage on November 18, 2025," detailing the cause as a bug in the bot migration service.](https://ss.rapidrecap.app/screens/fYzMBowlFtQ/00-00-48.png)
![Screenshot at 02:45: Screenshot of the S1ngularity Postmortem detailing the compromise of several NPM packages via a GitHub Actions injection vulnerability.](https://ss.rapidrecap.app/screens/fYzMBowlFtQ/00-02-45.png)
![Screenshot at 05:18: Slide from WatchTower research titled "Stop Putting Your Passwords Into Random Websites \(Yes, Seriously, You Are The Problem\)," warning against using unvetted online tools.](https://ss.rapidrecap.app/screens/fYzMBowlFtQ/00-05-18.png)
![Screenshot at 05:51: Visual evidence of leaked secrets on GitHub, showing repositories named 'Sna-Hulud: The Second Coming' containing sensitive information.](https://ss.rapidrecap.app/screens/fYzMBowlFtQ/00-05-51.png)
