Shai-Hulud code drop: It’s open season
ID: a76a63c0-c826-5b15-a60c-15b000fea620
STIX ID: report--a76a63c0-c826-5b15-a60c-15b000fea620
Feed Name: ReversingLabs Blog
TeamPCP publicly released the Shai-Hulud malware source code and researchers observed an active supply-chain campaign (the “Mini Shai-Hulud” attacks) that has compromised 150+ npm and PyPI packages; Shai-Hulud is a comprehensive offensive framework that harvests secrets (GitHub tokens, cloud credentials, npm tokens), poisons CI/CD pipelines and packages, persists via background services and a deadman switch, and exfiltrates data to attacker-controlled endpoints, substantially raising the risk of widespread, reusable supply-chain compromises and copycat variants.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
