The npm Threat Landscape: Attack Surface and Mitigations
ID: e48d6a11-8899-571c-a571-9e477dedc535
STIX ID: report--e48d6a11-8899-571c-a571-9e477dedc535
Feed Name: Palo Alto Networks Unit 42
Unit 42 documents a high-impact, wormable npm supply-chain campaign (Shai-Hulud) that impersonated legitimate packages (e.g., @bitwarden/[email protected]) to install a Bun-based payload which harvests npm/GitHub tokens and cloud secrets, exfiltrates data via an encrypted C2 and staged GitHub repos, and self-propagates by backdooring packages and injecting malicious preinstall hooks; the report provides technical analysis, IoCs (domains, IPs, hashes, GitHub artifacts), attribution to TeamPCP, and detailed mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
