Snipping the Long Tail of Shai-Hulud 2.0
ID: bbd0c122-4d0b-5c4b-b8f8-01f9ce690207
STIX ID: report--bbd0c122-4d0b-5c4b-b8f8-01f9ce690207
Feed Name: Wiz Blog
**Shai-Hulud 2.0 (sha1-hulud)** is a large-scale supply-chain worm that infected tens of thousands of repositories (including over one-third of the Fortune 100), persisted for weeks through private registries, local caches, and a malicious OpenVSX IDE extension, and exfiltrated vast numbers of secrets (GitHub, npm, cloud, and AI keys); the report links these exfiltrations to downstream impacts such as a $7M Trust Wallet theft and provides indicators, root causes, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
