Shai-Hulud Is Back, and This Time It Ate the Whole Ecosystem
ID: ad7bab8b-fdcc-570a-8a15-1c151e3cfc2e
STIX ID: report--ad7bab8b-fdcc-570a-8a15-1c151e3cfc2e
Feed Name: TrustedSec blog
Shai-Hulud is a widespread npm supply-chain campaign that compromised the atool account to push malicious preinstall/postinstall hooks across 300+ AntV ecosystem packages (impacting tens of millions of downloads). The payload harvests CI and local secrets (including scraping /proc memory for ACTIONS_ variables), sweeps hundreds of credential locations, exfiltrates via GitHub API dead-drops and a fallback OpenTelemetry-like C2 domain, and installs persistent VS Code/Claude backdoors; the report provides IOCs, hunt queries, detection rules, and step-by-step remediation (pin/downgrade, rotate credentials after cleanup, rebuild runners).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
