Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages
ID: a88fe8f2-1fbb-5a8a-bf48-7ae8e0536a67
STIX ID: report--a88fe8f2-1fbb-5a8a-bf48-7ae8e0536a67
Feed Name: HackRead
A fast-moving software supply-chain campaign injected a Shai-Hulud infostealer into Keyv and hundreds of npm packages by pushing malicious files and a "preinstall" lifecycle script to maintainers' repositories; the payload harvests npm/GitHub tokens, cloud keys, Vault tokens, private keys, and service tokens, then exfiltrates data to a public GitHub repo or fallback host. The campaign propagated by abusing package publishing and stolen credentials, affecting hundreds to over a thousand packages with combined billions of monthly downloads; organizations should treat any workstation or CI that executed affected versions as credential-exposed, remove affected releases, rotate credentials, inspect repositories and logs, and trigger immediate rescans.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
