Moneycontrol
HomeTechnologyWhy CERT-In is warning startups and IT firms about ‘Shai-Hulud,’ a Dune-inspired malware

Why CERT-In is warning startups and IT firms about ‘Shai-Hulud,’ a Dune-inspired malware

India’s cybersecurity agency warns of a fast-spreading npm supply chain worm, urging startups and ITes firms to secure credentials and audit dependencies.

September 26, 2025 / 10:55 IST
Story continues below Advertisement
The Indian Computer Emergency Response Team is the nodal body for cybersecurity in India under the Ministry of Electronics and Information Technology

India’s cybersecurity nodal agency, the Indian Computer Emergency Response Team (CERT-In), is concerned about startups regarding a fantastical creature from Dune, Shai Hulud.

However, unlike the giant sandworms in the Frank Herbert-written sci-fi novel series, Shai  Hulud, here, is a malware that poses a great risk for startups, IT companies and others.

Story continues below Advertisement

What is the Shai Hulud malware campaign?

This malware campaign targets JavaScript's node package manager (npm) ecosystem — the world’s largest collection of open-source software building blocks used by developers to create apps, websites, and digital services.