Shai Hulud 2.0, now with a wiper flavor
ID: 420c1201-d6ab-5187-a1c3-af42f79e19ce
STIX ID: report--420c1201-d6ab-5187-a1c3-af42f79e19ce
Feed Name: Securelist by Kaspersky
Kaspersky describes Shai Hulud 2.0, a two-stage worm that infects npm packages by abusing developer npm tokens: an unobfuscated bootstrap (setup_bun.js) installs a Bun runtime which runs a large obfuscated payload (bun_environment.js) that harvests GitHub and cloud credentials, exfiltrates data to attacker-controlled GitHub repositories, self-replicates by injecting malicious files into maintainers' packages and republishing them, and — if unable to exfiltrate — triggers destructive file-wiping; over 800 packages were infected and Kaspersky blocked more than 1,700 attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
