Can We Talk About This Now? Shai-Hulud Wave 2 Targeting npm
ID: 0ebaa17a-284b-51c5-b64a-62bf8fe83e44
STIX ID: report--0ebaa17a-284b-51c5-b64a-62bf8fe83e44
Feed Name: Morphisec Blog
This Morphisec blog describes the evolution of the Shai-Hulud npm supply-chain worm from a credential-stealing Wave 1 to a more destructive, self-replicating Wave 2 that reportedly infected 25,000+ repositories, added wiper functionality that can destroy home directories if exfiltration fails, used Docker-based privilege escalation to gain root, and persisted via malicious GitHub workflows and self-hosted runners; the post urges immediate scanning for compromised packages/workflows, credential rotation, least-privilege restrictions, and deployment of pre-execution runtime protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
