Threat intel · 27 August 2026 · 7 min read
The worm in the software parts — in plain language
Your website is assembled from ready-made parts taken from a public warehouse on the internet. A worm poisoned hundreds of them — the story, told without technical words.
ClearSecurity Vision
This article is about an attack with a strange name — Shai-Hulud, christened after the giant worm in “Dune” — that hit the world of programmers. Stay anyway: the story reaches your company by a surprisingly short road. And at a few points along the way, the decision is yours.
The parts warehouse
Your company’s website has, say, a contact form, a booking calendar and a shopping cart. The agency that built it didn’t write any of them from scratch: it took them ready-made, for free, from a public warehouse on the internet — a place where programmers from all over the world pool pieces of software that anyone can reuse. That’s how software is built everywhere: fast, cheap and, as a rule, well. Nobody casts their own screws.
One detail matters for our story: the warehouse runs on trust. When the agency takes a part from there, it doesn’t take it apart screw by screw to see what’s inside. It fits it.
What the worm did, step by step
In the autumn of 2025, someone put poison into exactly this kind of part. Here is its journey, in four steps:
- An ordinary programmer — let’s call him Radu, he works at a web agency — picks up his parts from the warehouse in the morning, like every day. This time, one of them has poison inside.
- The poison steals Radu’s keys. Not his office keys — the passwords and the “badge” Radu himself uses to publish parts to the warehouse.
- With Radu’s badge, the poison puts itself into HIS parts. From now on, anyone who takes a part made by Radu goes through what Radu went through at step 1. And they, too, have parts in the warehouse…
- And so on, with no one at the controls. That’s why they called it a worm: it multiplies by itself, like an epidemic. Within days — hundreds of poisoned parts, and some of the stolen passwords and keys published in plain sight on the internet, within anyone’s reach.
You have never heard of Radu. You couldn’t have, and you didn’t need to. But if your agency fitted one poisoned part into your website, the poison is now inside your house — brought in by a man you’ve never seen, employed by a company you never signed anything with.
Your company doesn't produce software. Does this story concern you?
A. No. It's a problem between programmers and their warehouse — we merely use the programs.
That's precisely the trap: "merely using" means the poison reaches you ready-fitted, through the website or app built by others. The final victims of these attacks are almost always companies that were "merely using".
B. Yes — our website and apps are assembled by others, from parts nobody at our company ever sees. The right question is what OUR suppliers are doing about it.
Exactly. You don't need to understand the parts — you need to know who fits them for you and be able to ask three simple questions (coming below). The law thinks the same way: taking care of your suppliers is among the minimum measures under NIS2.
C. I'll care if the news says it hit companies in our country.
The poisoned part doesn't know which country the website it was fitted into is in — it goes wherever the warehouse takes it, which is everywhere. By the time it "makes the local news", the poison has usually been installed for weeks.
The day the questionnaire arrives
The worm struck in 2025, but for ordinary companies the story only knocked on the door in 2026 — in the shape of paperwork. Large companies, legally required to check their suppliers, started sending out forms: “Confirm that you were not affected by the Shai-Hulud campaign”. The form travels down the chain, company by company — and sooner or later it reaches one that has never written a line of code. Yours, for example: your biggest client, your bank or your insurer sends it over, with a two-week deadline. The contract may depend on the answer.
The questionnaire has arrived. What do you do?
A. Answer "we were not affected" by reflex. We have no programmers, so there's nothing to check.
You've signed a statement you cannot prove. If it later comes out that your website, built by the agency, contained a poisoned part — you've turned a technical incident into a trust problem with your biggest client.
B. Forward the question, in writing, to the people who built and maintain our website and apps — and ask for an answer in writing too.
That's the right move: the questionnaire isn't about what you know, it's about what your suppliers can prove. Their written answer becomes your evidence. This is exactly what the "supply chain care" required by NIS2 looks like in practice.
C. Leave it unanswered — maybe they'll forget about it.
They won't: your client needs the answer for their own legally required file. Silence reads as "they have something to hide" — and it's the kind of reason why, at contract renewal, "we've decided to work with someone else" suddenly appears.
The three questions for your agency
You don’t need technical knowledge to ask them — and a serious supplier answers all three without taking offence:
- “Do you check the parts you fit into our website?” — automated tools exist that do exactly this: they look at every part used and raise the alarm on the ones with known problems. The only question is whether they’re switched on.
- “If a part used on our site turns out to be poisoned, how quickly do we find out?” — a good answer comes with a concrete timeframe (“we notify you within 24 hours”); a bad answer sounds like “it hasn’t come up”.
- “Can you give us in writing what you checked after Shai-Hulud?” — that piece of paper is what gets you out of trouble when the questionnaire above arrives.
3 things to do tomorrow morning
- Make the list of everyone who touches your software: who built your website, who maintains it, who runs your online shop, where your apps are hosted. In an incident like this, that list is your map.
- Ask the three questions above at least of your main supplier. In writing. The answers live in the same folder as the contracts.
- Decide today who answers security questionnaires coming from clients. One person, one address — so the form doesn’t wander between departments for three weeks while the deadline runs.
The short moral
The worm in Dune swallowed everything that moved in the desert; this digital one swallowed passwords and software parts. The lesson for an ordinary company isn’t about worms — it’s that “your” software has passed through the hands of a whole line of people you have never met, and their door is your door too. You can’t guard the warehouse yourself. You can, however, know who fits your parts — and ask them three good questions once a year.
newsletter
Get new articles by email.
NIS2 compliance, incident reporting and plain-language security — only when we publish something new. No spam, unsubscribe anytime.