npm Supply Chain Attack: Shai-Hulud Malware Variant Compromises 23 Packages, Steals 408 GitHub Repository Credentials on June 25

According to Slow Mist Security Team, a new variant of the Shai-Hulud/Miasma/Hades npm malware on June 25 is targeting the npm ecosystem through a compromised developer account, czirker. The attack exploits a preconfigured binding.gyp file to execute malicious code during npm install. To date, 23 affected packages have been confirmed, with leo-logger recording 3,140 weekly downloads. The team identified 408 GitHub repositories containing stolen credentials. Attackers can steal GitHub tokens, npm tokens, AWS/GCP/Azure credentials, and exfiltrate local environment data to further propagate through the npm supply chain.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments