Shai-Hulud malware infects 500 npm packages, leaks secrets on GitHub
ID: c389c2dc-e35d-5f06-967c-1211d798f433
STIX ID: report--c389c2dc-e35d-5f06-967c-1211d798f433
Feed Name: Bleeping Computer
**Shai-Hulud supply-chain campaign:** A widespread campaign has trojanized npm packages (hundreds to tens of thousands of versions) to steal developer and CI/CD secrets, automatically posting stolen data to GitHub; the malware uses heavy obfuscation, contains files like setup_bun.js and bun_environment.js, can exfiltrate tokens for GitHub, npm and cloud providers, and includes a destructive home-directory overwrite if certain conditions fail — organizations should identify and replace compromised packages, rotate credentials, and disable npm postinstall scripts in CI where possible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
