170 npm Packages Hijacked to Steal GitHub, AWS & Kubernetes Secrets
ID: 6a7b16b6-b14c-5fbb-8dc5-1d0ac6013ed2
STIX ID: report--6a7b16b6-b14c-5fbb-8dc5-1d0ac6013ed2
Feed Name: GBHackers
**Executive summary:** Attackers compromised more than 170 npm packages and two PyPI libraries, embedding preinstall/import‑time loaders and heavily obfuscated payloads that steal GitHub, npm, cloud (AWS/GCP/Azure), Kubernetes, Vault, and local developer credentials, propagate by abusing CI/CD publishing tokens to republish infected packages, and include destructive features such as a dead‑man switch and system‑wiping second stages; JFrog linked the activity to the "Shai‑Hulud" family and observed rapid, worm‑like spread despite detection and blocking within 24 hours.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
