New Shai-Hulud malware wave compromises 600 npm packages
ID: 8a983e35-44a6-5280-8d88-5c0953dcd753
STIX ID: report--8a983e35-44a6-5280-8d88-5c0953dcd753
Feed Name: Bleeping Computer
Threat Score
The Shai-Hulud supply-chain campaign published hundreds of malicious npm package versions (over 600 packages / 323 unique packages reported) to steal developer and CI/CD secrets, exfiltrating data via a Session P2P network and GitHub repositories; the malware is obfuscated, encrypts stolen data, can self-propagate by republishing infected packages, and abuses OIDC tokens to create apparently valid Sigstore provenance attestations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
