Shai-Hulud Malware Escalates: 600 npm Packages Compromised in Latest Supply Chain AttackShai-Hulud Malware Escalates: 600 npm Packages Compromised in Latest Supply Chain Attack
TL;DR
- •A new wave of Shai-Hulud malware compromised 600+ npm packages, primarily within the @antv ecosystem.
- •The malware steals secrets from developer environments and CI/CD pipelines, exfiltrating data via Session P2P and GitHub.
- •Attackers are leveraging compromised tokens to create rogue GitHub repositories and are now generating valid Sigstore provenance.
source:
Read full post npm Supply Chain Attack Self-Spreads, Targeting Auth Tokensnpm Supply Chain Attack Self-Spreads, Targeting Auth Tokens
TL;DR
- •A new npm supply-chain attack is spreading through infected packages.
- •The attack targets authentication tokens stored in environment variables.
- •Developers should review dependencies and environment variable usage.
source:
Read full post End of results for this topic.