SECURITYCYBERSCOOP
Massive supply-chain attack compromises 440 packages under four hours
An attacker compromised a GitHub maintainer account and injected malicious code into over 440 npm packages within four hours using a self-replicating worm based on the Mini Shai-Hulud repository. The malware targeted credentials and sensitive data, affecting packages like keyv, flat-cache, and file-entry-cache, which are present in 46% of cloud environments.
Mentioned
Related Signal
Adjacent reporting
- New Shai-Hulud malware wave compromises 600 npm packages
- ‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack
- Hackers have compromised dozens of popular open source packages in an ongoing supply chain attack
- The never-ending supply chain attacks worm into SAP npm packages, other dev tools
- Megalodon chums the waters in 5.5K+ GitHub repo poisonings
- Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos