VC
Value Add VC
⚡HomePulse⚡Helpful Apps📝Blog🤝Partner
Illustration for: The npm Worm Passed a Real Security Check, Not a Fake One
Value Add VC/Pulse/AI

The npm Worm Passed a Real Security Check, Not a Fake One

New analysis of the Shai-Hulud npm worm finds it did not forge its provenance attestation -- it earned a legitimate one by running inside a compromised maintainer's own CI pipeline, which is worse.

TC
By the AI Desk
Edited by Trace Cohen · Early-stage VC & angel · Founder, New York Venture Partners
August 5, 2026
1 min read
ShareXLinkedInEmail
TC

The VC Read · Trace's Take

Trace Cohen

Provenance proves origin, never intent -- and an entire security category has been sold on the implication that the two are the same. If you're a CISO, the action item is scoping: a publish token that can also reach production secrets is the whole blast radius. If you're funding supply-chain security, the wedge just moved from "verify where this came from" to "decide whether this build should ship," and almost nobody is selling the second one yet.

Analysis

VentureBeat reported that the Shai-Hulud npm worm did not counterfeit the supply-chain provenance signals defenders rely on. It obtained genuine ones, because the malicious publish executed inside a legitimate maintainer's CI pipeline using that maintainer's real credentials.

This inverts the defensive model most engineering organizations adopted after the 2021-2024 wave of npm attacks. Sigstore-backed provenance attestations, SLSA levels and signed builds all answer one question: did this artifact come from the repository and pipeline it claims to come from? Shai-Hulud's answer is yes. The attestation is accurate. The build was authentic. The code inside it was hostile.

“This inverts the defensive model most engineering organizations adopted after the 2021-2024 wave of npm attacks.”

The attack path is the one every organization with automated publishing shares. A maintainer token is stolen, the attacker pushes a commit, CI builds and signs and publishes it, and the resulting package arrives in downstream installs carrying a valid chain of custody. Provenance proves origin; it was never designed to prove intent, and treating a green attestation as a safety verdict is the mistake being exposed here.

Practical consequences for engineering teams: attestation checks belong in the pipeline but cannot be the last gate. Pinned versions with integrity hashes, delayed adoption windows for new releases of critical dependencies, and CI credentials scoped so a publish token cannot also reach production secrets all matter more than the badge. GitHub, npm and the OpenSSF have all pushed provenance as the answer for three years; this is the case that shows what it does not cover.

What to watch: whether npm introduces publish-time behavioral analysis rather than origin verification alone, and whether the major package registries adopt mandatory two-person review for releases of high-download packages. Until then, an authentic signature on a hostile package is a repeatable attack, not a one-off.

ShareXLinkedInEmail

Reported by VentureBeat · Analysis by Value Add Pulse.

← Back to Pulse

THE WIRE in your inbox— Tech, startup & VC news with Trace's take. Free, no spam.

Read Next

AI· Aug 13, 2026

Anthropic in Talks to Buy AI Video Startup Decart for $6B

Illustration for: Anthropic in Talks to Buy AI Video Startup Decart for $6B
AI~$6B acquisition talks

Anthropic in Talks to Buy AI Video Startup Decart for $6B

Anthropic is negotiating to buy Israeli startup Decart, which builds real-time video-generation models and GPU-efficiency software, for roughly $6 billion in what would be Anthropic's largest acquisition ever.

AI· Aug 13, 2026

DeepSeek Ships V4 Pro, Its Sharpest Agent Model Yet

Illustration for: DeepSeek Ships V4 Pro, Its Sharpest Agent Model Yet
AI

DeepSeek Ships V4 Pro, Its Sharpest Agent Model Yet

DeepSeek took V4 Pro 0813 to general availability with sharply improved agentic benchmarks, but the vendor-reported gains haven't been independently replicated and a price hike lands within days.

AI· Aug 12, 2026

Google DeepMind's Talent Exodus Reveals a Deeper Identity Crisis

Illustration for: Google DeepMind's Talent Exodus Reveals a Deeper Identity Crisis
AI

Google DeepMind's Talent Exodus Reveals a Deeper Identity Crisis

Days after Demis Hassabis stepped down as DeepMind CEO, Fortune reports stalled models, missed deadlines and staff burnout drove the exodus, with engineers telling the outlet DeepMind is losing its separation and identity within Alphabet.

@Trace_Cohen·t@nyvp.com