Fast-Moving Shai-Hulud Attack Infects npm Packages with 2 Billion Monthly Downloads
Researchers at Aikido Security and Endor Labs are tracking a fast-spreading supply-chain attack that is compromising a wide range of npm software packages that combined have more than 2 billion installs a month and is stealing a wide range of secrets and other information. According to Ilyas Makari, malware researcher with Aikido, the bad actor […]
A supply-chain attack has compromised a large number of npm software packages, with combined monthly downloads exceeding 2 billion. The attack, which researchers are linking to the Shai-Hulud worm, involves stealing secrets and other information from victims' systems. The breach was carried out by compromising the GitHub account of a key-value storage library's maintainer and then pushing malicious files directly to the main branch, resulting in the release of infected versions to npm.
Aikido Security and Endor Labs researchers have reported that the attack is spreading rapidly, with over 1,280 packages infected within a short period of time. The malware injects two files, setup.mjs and Math_Symbol.js, into affected packages, which automatically execute before a successful installation. setup.mjs downloads a JavaScript runtime and executes the real payload, Math_Symbol.js, which is an obfuscated file containing credential stealers.
These stealers target various secret stores in victims' systems, such as npm and GitHub tokens, AWS credentials, Kubernetes secrets, HashiCorp Vault tokens, and Stripe and Slack tokens. The attack targets not only individual developers but also organizations, including Deliveroo, OneReach, ServiceTitan, Picsart, and Qlik. To mitigate the threat, organizations are advised to pin or roll back infected packages, rotate credentials, search lockfiles and CI logs for malicious versions, and use npm, yarn, and pnpm overrides for keyv, flat-cache, and file-entry-cache.
Written by urgent.news from DevOps.com's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.