Dead Man’s Switch – Widespread npm Supply Chain Attack Driving Malware Attacks
ID: 1d6bf73e-6a38-5c9b-901a-2d9625302f60
STIX ID: report--1d6bf73e-6a38-5c9b-901a-2d9625302f60
Feed Name: cybersecurityNews.com
GitLab’s Vulnerability Research team uncovered a large-scale npm supply-chain campaign delivering an evolved "Shai-Hulud" malware that installs a disguised 10MB payload which harvests GitHub/npm/AWS/Google/Microsoft credentials, uses stolen npm tokens to autonomously republish infected packages (worm-like spread), and includes a destructive cleanup/wiper that triggers if infected hosts lose access to attacker-controlled GitHub/npm infrastructure—potentially causing mass data destruction; GitLab recommends enabling dependency scanning and monitoring for suspicious npm preinstall scripts and unusual version changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
