Inside Shai-Hulud’s Maw: How The NPM Worm Exploits And Propagates
ID: 88f08b43-872d-540f-ba58-cf53703de0e9
STIX ID: report--88f08b43-872d-540f-ba58-cf53703de0e9
Feed Name: Checkmarx Zero
This report analyzes the Shai-Hulud NPM worm and its evolved variant “The Second Coming,” describing how the malware steals developer credentials and cloud secrets, propagates through injected package scripts and GitHub workflows, exfiltrates data to attacker-controlled repositories, tampers with host/network security, and installs a self-hosted GitHub Actions runner as a persistent backdoor; the second version adds stronger obfuscation, broader cloud targeting (including Azure), destructive fallback (wiping user profiles), and privilege-escalation/network tampering behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
