logo

Supply Chain Attack Targeting Several NPM Packages to Harvest Credentials

ID: fcb4ee7b-d8ed-5b24-a48f-b8c2fce5cf3c

STIX ID: report--fcb4ee7b-d8ed-5b24-a48f-b8c2fce5cf3c

Feed Name: Kudelski Security

Threat Score
80/100

Date Published: 2025-09-19

Date Updated: 2026-07-24

...
...

A coordinated NPM supply-chain campaign (Shai-Hulud) trojanized more than 40 packages — including packages published under a CrowdStrike account — by injecting a malicious bundle.js executed on npm install to harvest GitHub, AWS, GCP, Azure, and NPM credentials, propagate by forcing republishing of packages, and persist via malicious GitHub Actions that exfiltrate secrets to a webhook; affected packages were removed and the report provides IoCs, hunting queries, and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.