home.social

#shaihulud — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #shaihulud, aggregated by home.social.

fetched live
  1. Aikido reports that Tensorlake version 0.5.144, published on October 8, is malicious.

    It runs during installation, before the package is used, and tries to steal access credentials and spread to other projects.

    Aikido links it to a new Shai-Hulud variant.

    The package has more than 100,000 installs overall, but that is not the install count for this specific version.

    Aikido says its analysis found no signs of compromise…

    en.hacks.gr/kakovoyli-ekdosi-t

    #Tensorlake #ShaiHulud #npm #MaliciousPackages

  2. Tensorlake package version 0.5.144 contained Shai-Hulud, a malicious program designed to collect access credentials and publish infected versions of other packages the user’s account could access.

    Socket says it searched files and systems used by developers and companies for sensitive information.

    The release is no longer available, and those who installed it are urged to remove it and change access details that may ha…

    en.hacks.gr/i-ekdosi-0-5-144-t

    #Tensorlake #ShaiHulud #npm #SoftwareSupplyChain

  3. Před rokem začal registrem npm procházet samošířící červ Shai-Hulud. Od té doby se útoky na dodavatelský řetězec JavaScriptu staly pravidelnou záležitostí a npm postupně přepisuje pravidla publikování. Projdeme, co se za ten rok stalo, jak dnes bezpečně publikovat balíček, co musíte stihnout do ledna 2027 a jak se bránit jako uživatel balíčků.

    https://zdrojak.cz/clanky/rok-po-shai-hulud-co-se-zmenilo-na-npm-a-co-musite-udelat-do-ledna/
  4. Two actions-cool GitHub Actions compromised in the May Mini Shai-Hulud campaign became accessible again on Sept 16 with tainted tags still intact, before GitHub re-disabled them. It shows restored repos can silently revive known supply-chain payloads if tags are not purged. #SupplyChain #GitHubActions #ShaiHulud

    cyberworldops.eu/en/restored-g

  5. 📢 Shai-Hulud : un payload npm identique réapparu après 111 jours de dormance

    Le 19 mai 2026, une attaque de chaîne d'approvisionnement baptisée Shai-Hulud avait compromis des comptes mainteneurs npm pour publier 639 versions malveillantes de packages @antv en l'espace d'une heure. Le payload avait été rapidement analysé et fingerprinted par la communauté de…

    📖 cyberveille : cyberveille.ch/posts/2026-09-1
    🌐 source : aikido.dev/blog/shai-hulud-npm
    🟢 vérification factuelle haute
    #ShaiHulud #npm #Cyberveille

  6. GitGuardian reports that the latest Shai-Hulud variant searches for access credentials in 469 locations across software development environments, compared with 189 in earlier versions.

    The scope includes tool configuration, automated build and publishing systems, remote infrastructure and AI-tool settings.

    A stolen credential may expose source code, provide access to other systems or enable software publication, de…

    en.hacks.gr/to-shai-hulud-psac

    #ShaiHulud #GitGuardian #GitHub #SoftwareSupplyChain

  7. Shai-Hulud Infostealer Worm Targets 469 Credential Locations, Threatens Software Supply Chains

    A recent Shai-Hulud infostealer worm variant has significantly upped the ante, now scanning 469 credential locations - a massive jump from 189 in earlier variants - to harvest sensitive access credentials and threaten software supply chains. This strategic shift allows attackers to exploit…

    osintsights.com/shai-hulud-inf

    #InfostealerWorm #Shaihulud #SupplyChain #CredentialHarvesting #MalwareOperations

  8. Two alleged TeamPCP members have been arrested—but Shai-Hulud’s open-sourced supply-chain attack playbook remains a lasting threat. jpmellojr.blogspot.com/2026/08 #FBI #AFP #SupplyChainSecurity #cybercrime #shaihulud

  9. Two alleged TeamPCP members have been arrested in Australia and face 14 charges over supply chain attacks linked to #ShaiHulud and the theft of over 500,000 credentials.

    Listen/Read/Watch: hackread.com/police-arrest-tea

    #TeamPCP #ShaiHulud #CyberSecurity #CyberCrime #Australia

  10. ChainDrop Worm Infiltrates npm Supply Chain, Evades Defenses

    A sneaky new worm called ChainDrop has infiltrated the npm supply chain, infecting 444 packages that are downloaded a whopping 2 billion times each month. This stealthy attack uses a clever tactic, targeting package tarballs rather than repository source commits to evade defenses.

    osintsights.com/chaindrop-worm

    #NpmSupplyChain #Chaindrop #Shaihulud #SupplyChainAttack #EmergingThreats

  11. Six security outlets reported 868 npm packages compromised today. The source page now reads 434. Same timestamp, same 1,381 versions, exactly half the packages.

    I went to check the original. Nobody had archived it. Mine was the first snapshot in existence, six hours after the figure entered circulation.

    Five different counts for one event inside nine hours.

    onyxdigital.bearblog.dev/first
    #npm #supplychain #ShaiHulud #infosec #OnyxAudit

  12. Here we are again. Shai-Hulud has resurfaced with 28 malicious npm package versions across four unrelated enterprise namespaces, published in two bursts on Aug 4, all shipping the same credential-stealing payload (SSH keys, AWS creds, Jenkins secrets, /etc/shadow, and more).

    The twist this round: no hardcoded C2. The stealer resolves its exfiltration domain at runtime via an eth_call to an Ethereum smart contract, so the operator can rotate infrastructure without touching a single package. No malicious binary in the tarball either, it runs under a legitimately signed Bun runtime that gets deleted afterward.

    Full analysis + IOCs from Netskope Threat Labs:👇

    netskope.com/blog/npm-stealer-

    #npm #SupplyChain #ThreatIntel #ShaiHulud

  13. 📢⚠️ Researchers are tracking an active Shai-Hulud npm attack that compromised packages linked to Deliveroo and Qlik, infecting 50 to 100 new packages every few minutes.

    Listen/Read: hackread.com/shai-hulud-npm-wo

    #CyberSecurity #ShaiHulud #Malware #npm #CyberAttack

  14. ----------------

    🎯 Threat Intelligence
    ===================

    🔹 npm Supply Chain Escalation: From Shai-Hulud to Miasma RAT

    Unit 42's updated report documents a sharp escalation in npm supply chain attacks following the Shai-Hulud worm in September 2025. The worm automated compromise and redistribution of malicious packages, shifting npm attacks from isolated typosquatting to systematic, weaponized campaigns.

    🔹 Campaign Timeline

    April 2026: Two campaigns identified. "Shai-Hulud: The Third Coming" started April 22. "Mini Shai-Hulud" began April 29.

    May 2026: TeamPCP continued the Mini Shai-Hulud campaign with two new waves. One introduced a credential-free initial access technique. The other generated the highest single-hour package count of any Shai-Hulud worm to date. Copycat activity has since complicated attribution.

    June 2026: At least 32 packages under the @redhat-cloud-services npm namespace were compromised. The attacker bypassed code review entirely and pushed a payload named Miasma.

    July 2026: Attackers compromised release pipelines of four core AsyncAPI GitHub repositories on July 14. The campaign, calling itself miasma-train-p1, published five trojanized packages:
    • @asyncapi/[email protected]
    • @asyncapi/[email protected]
    • @asyncapi/[email protected]
    • @asyncapi/[email protected]
    • @asyncapi/[email protected]

    The payload is assessed as a descendant of the Miasma RAT.

    🔹 Core TTP Shifts

    1. Wormable propagation: Payloads steal npm tokens and GitHub PATs to automatically infect and republish legitimate packages, as seen in the March 2026 Axios compromise.

    2. Infrastructure-level persistence: Attackers embed into CI/CD pipelines for long-term, undetectable access to enterprise environments.

    3. Multi-stage payloads: Dormant sleeper dependencies activate only under specific environmental conditions, evading automated scanners.

    🔹 Attack Chain
    • Initial Access: Credential-free techniques, stolen npm tokens, GitHub PATs
    • Persistence: CI/CD pipeline compromise
    • Execution: Miasma RAT and descendants
    • Propagation: Automated republishing of trojanized packages
    • Evasion: Sleeper dependencies with conditional activation

    Monitor for campaign identifiers "miasma-train-p1" and "Shai-Hulud: The Third Coming" in infrastructure logs.

    🔹 npm #SupplyChain #ShaiHulud #MiasmaRAT #ThreatIntelligence

    🔗 Source: unit42.paloaltonetworks.com/mo

  15. Da un runner Jenkins ad Amazon Redshift: come il worm Shai-Hulud trasforma una CI/CD in una breach cloud

    FortiGuard Labs ricostruisce una compromissione partita da un pacchetto npm infetto da Shai-Hulud: in poche ore l'attaccante passa da un Jenkins runner a pieni privilegi amministrativi su AWS, fino a esfiltrare dati da un cluster Amazon Redshift in produzione.

    insicurezzadigitale.com/da-un-

  16. TeamPCP: как команда хакеров-любителей «Дюны» закинула в наши Node.js-пакеты червей Shai-Hulud

    npm install — такая привычная многим из читателей команда, но за последние пару месяцев она обернулась сущим кошмаром для инженеров по безопасности. И ладно бы всё сводилось к проверке 5 пакетов из package.json , но у каждой зависимости по 10 своих зависимостей, а у тех ещё по 10. В итоге мы тянем 2000, а не 5 пакетов, и тут, кажется, уже руками не проверишь. И именно на этой боли всех безопасников, поддерживающих JS-проекты, сыграла команда TeamPCP. В этой статье я хочу подробно, от А до Я, разобраться, в чём опасность, почему так произошло и как от этого защититься.

    habr.com/ru/companies/ruvds/ar

    #nodejs #shaihulud #teampcp #ruvds_статьи

  17. Current read

    Dune, Exploration Scientifique et Culturelle d'une Planète-Univers

    Directed by Roland Lehoucq

    #Dune #science #sciencefiction #scifi #astronomy #ShaiHulud #FrankHerbert #RolandLehoucq #book

  18. Worm operators don't work in Perl, apparently:

    $ perl -E 'say int(-int(~(int(13))))'
    -1.84467440737096e+19

    #ShaiHulud #Chrysknife

  19. Shai-Hulud Malware Targets Python Packages, Exposes Developer Secrets

    Hundreds of thousands of downloads of 19 popular Python packages were compromised in a massive supply-chain attack that stole developer secrets, courtesy of the Shai-Hulud malware. The malicious packages, disguised as useful bioinformatics and science tools, were actually designed to expose sensitive information.

    osintsights.com/shai-hulud-mal

    #Shaihulud #Malware #SupplyChain #Python #Pypi

  20. Grafana Breach Exposes Missed Security Step After TanStack Attack

    A single misstep in Grafana's security protocol allowed attackers to gain access to its GitHub repositories, following a supply-chain incident involving malicious TanStack packages. A missed GitHub workflow token proved to be the key that enabled the breach.

    osintsights.com/grafana-breach

    #SupplyChain #Github #Tanstack #Shaihulud #Grafana

  21. Massive npm Supply Chain Attack Hits AntV Ecosystem; Hundreds of JavaScript Packages Compromised A major software supply chain attack has compromised hundreds of widely used npm packages tied to th...

    #Cyber #News #Data #Breach #News #Hacker #News #AntV #npm #Shai-Hulud

    Origin | Interest | Match
  22. Shai-Hulud Malware Targets 600 Npm Packages in Supply-Chain Attack

    In a shocking supply-chain attack, malicious Shai-Hulud malware targeted a staggering 600 npm packages, with researchers uncovering nearly 640 tainted versions across 323 unique libraries in just one hour. The assault hit popular ecosystems like @antv and spread to widely-used packages, leaving a trail of poisoned code in its wake.

    osintsights.com/shai-hulud-mal

    #SupplyChainAttack #Shaihulud #Npm #MalwareOperations #EmergingThreats

  23. Endor Labs detected 600+ malicious package versions forging valid Sigstore provenance. If you installed affected packages May 19, rotate all credentials now.

    37 @antv/* packages. 27 minutes. One stolen token. Full IOC list:
    endorlabs.com/learn/mini-shai-

    #ShaiHulud

  24. Shai-Hulud worm infects another npm package

    A copycat of the notorious Shai-Hulud worm has struck again, infecting another npm package by exploiting a GitHub Actions misconfiguration. This latest attack follows a similar pattern that recently prompted TanStack to rethink its approach to accepting outside code contributions.

    osintsights.com/shai-hulud-wor

    #Shaihulud #Npm #GithubActions #SupplyChain #MalwareOperations

  25. Research reveals that #TeamPCP hijacked OIDC tokens to poison hundreds of TanStack, Mistral AI, and UiPath packages with the self-propagating Mini Shai-Hulud worm.

    Read: hackread.com/teampcp-mini-shai

    #CyberSecurity #Malware #ShaiHulud #CyberAttack #npm

  26. More supply chain attacks incoming! Exciting! We are so fudged! Maybe, we''ll see.

    From the Telegram channel of Breached/BreachForums:

    Breached has teamed up with TeamPCP to host the first ever supply chain competition! Whoever is able to conduct the biggest supply chain operation using the now open source Shai Hulud worm will be congratulated and will receive a prize of $1000 USD in XMR from @diencracked. Make sure to read the rules posted in the announcement first.

    #Supplychain #TeamPCP #ShaiHulud #ShaiHuludWorm

  27. I didn’t know that this was even possible: A #Python package was compromised by #malware. The @pypi package #lightning versions 2.6.2 and 2.6.3 reportedly executed credential-stealing code on import:

    🌍 semgrep.dev/blog/2026/maliciou

    What does this mean for all other Python packages? Do we need package #virus scanners now?

    #PyPI #CyberSecurity #DataScience #OpenSource #ShaiHulud #PyTorch

Share on Mastodon

Enter the server where you have an account.