Shai-Halud Supply Chain Campaign — Expanded Impact & Vercel Response
Over 40 npm packages pwned in coordinated supply chain attack. Vercel just disclosed how they caught it—and what founders need to do now.

Why it matters
A major coordinated supply chain attack (Shai-Halud) compromised 40+ npm packages via wallet-drainer malware. While Vercel contained blast radius to ~10 customer projects, the incident exposes systemic risks in open-source dependency chains that every AI/tech startup relies on—and demands immediate token rotation and lockfile audits across infrastructure.
The key facts
8 to know40+ npm packages compromised via Tinycolor 'worm' vector
Original Qix compromise affected ~18 core packages (chalk, debug, ansi-styles)
CrowdStrike npm namespace also trojanized with wallet-drainer malware
~10 Vercel customer projects directly impacted by compromised versions
DuckDB maintainer account compromised; no Vercel customer builds affected
Attack timeline: Sept 8 discovery → Sept 16 public disclosure (8-day window)
Vercel response: blocklisted versions, purged caches, elevated monitoring thresholds
Recommended mitigation: pnpm minimumReleaseAge setting (24hr delay), token rotation, lockfile pinning, GitHub workflow inspection
Go to the source
Vercel Blogvercel.com
Publisher excerpt: Summary Impact to Vercel Customers What We Did What We’re Watching & Doing Recommendations for Vercel Users Timeline References The supply chain campaign has escalated. What began with the Qix compromise affecting ~18 core npm packages (, , , etc.) has since spread:Shai-Haludchalkdebugansi-styles…