Interview #10 diencracked (BreachForums owner)
ID: 3340c2dd-485b-5bc4-91a7-5f116baea3f4
STIX ID: report--3340c2dd-485b-5bc4-91a7-5f116baea3f4
Feed Name: deepdarkCTI
This interview with the BreachForums operator 'diencracked' details the Shai Hulud JavaScript worm—its functionality (postinstall/preinstall package trojanization, credential harvesting, automated republishing, and persistence via GitHub Actions), documented waves infecting hundreds to tens of thousands of repositories, and an active forum-sponsored supply-chain competition offering a Monero prize that incentivizes further attacks; the operator also describes partnerships with TeamPCP, Vect ransomware, use of AI in tooling, and plans to expand offensive services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
