In this episode of The Secure Disclosure, host Mackenzie Jackson is joined by security experts Charlie Erikson, Daniel Pereira, Gaetan Ferry, and Martin Knobloch to dissect the Shai-Hulud campaign—a self-propagating malware worm that compromised npm and GitHub repositories. The discussion covers: How the attack was first discovered (and ignored) The challenges of raising alarms in the security community A deep dive into the malware’s tactics and propagation methods The massive impact on open-source repositories and secrets exposure We also have broader conversation on Shift Left security, its failures, and how developers and security teams can better collaborate Resources Social Media Mackenzie Jackson -https://www.linkedin.com/in/advocatemack/ Daniel Pereira - https://www.linkedin.com/in/daniel-pereira-b17a27160/ Charlie Erikson - https://www.linkedin.com/in/charlie-eriksen-a318578/ Gaetan Ferry - https://www.linkedin.com/in/gaetan-f-a40497a4/ Martin Knobloch - https://www.linkedin.com/in/martin-knobloch/ Chapters 00:00 – Introduction with Mackenzie Jackson 00:18 – Overview of the Shai-Hulud campaign 02:30 – Daniel Pereira: The discovery and struggle to raise alarms 12:20 – Charlie Erikson: Technical breakdown of the Shai-Hulud malware 17:05 – Gaetan Ferry: Postmortem insights and repository exposure 25:32 – Sponsor Segment: Aikido Security & SafeChain 26:30 – Martin Knobloch: The realities of “Shift Left” security