Sha1-Hulud: The Second Coming of The New npm GitHub Worm
ID: 57443c49-b328-5e3e-8843-c5732f59d686
STIX ID: report--57443c49-b328-5e3e-8843-c5732f59d686
Feed Name: LevelBlue SpiderLabs Blog
Sha1-Hulud has re-emerged with a supply-chain attack targeting npm packages: infected packages include a preinstall loader (setup_bun.js) that runs an obfuscated payload (bun_environment.js) to harvest credentials (tokens, API keys, cloud creds), use discovered npm tokens to republish and poison the victim’s maintained packages (worm-like propagation), create public GitHub repositories to exfiltrate data, abuse GitHub Actions to execute arbitrary commands locally, and include a destructive self‑destruct that overwrites/shreds user files; nearly 1,000 packages and tens of thousands of repositories are reported impacted and multiple SHA256 IoCs are listed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
