“Old Father Eternity”: Shai-Hulud Worm Strikes a 6th Time – keyv/cacheable npm Supply Chain Attack
ID: 20dca371-7b0e-5fe2-8a8a-7717114a615e
STIX ID: report--20dca371-7b0e-5fe2-8a8a-7717114a615e
Feed Name: Checkmarx Zero
Checkmarx Zero reports an active, large-scale npm supply-chain campaign (a Shai-Hulud variant) that injects malware into widely used packages (e.g., keyv, cacheable), steals credentials from over 200 file paths and cloud metadata endpoints, and self-propagates across npm packages and GitHub repositories using sophisticated multi-channel C2 (including an Ethereum smart contract and GitHub commits). The report includes IoCs (malicious filenames, hashes, domains, an Ethereum address, malicious workflow/branch names), lists affected package versions, outlines the six-stage attack chain, and provides containment and remediation steps including credential rotation, artifact scanning, and blocking malicious package versions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
