FAQ: The Shai-hulud npm worm attack explained
ID: 65f4569f-cc2d-5f1d-bbfc-857b5a844597
STIX ID: report--65f4569f-cc2d-5f1d-bbfc-857b5a844597
Feed Name: ReversingLabs Blog
Shai-hulud is a self-propagating worm observed in the npm registry that compromises maintainer accounts to add malicious postinstall scripts which execute a bundle that searches for and exfiltrates environment tokens (npm, GitHub, AWS, GCP) and attempts to copy private GitHub repos; attackers exfiltrate data to attacker-created GitHub repositories and propagate by automatically publishing infected versions of packages, affecting hundreds of projects including high-download libraries and prompting recommendations for improved registry controls, 2FA, token hygiene, and automated detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
