< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 7 sources · 1 days · First seen · Last updated

npm ecosystem supply chain attacks

Overview

A significant software supply chain attack has targeted the npm ecosystem, affecting hundreds of packages. Initial reports identified a wave of the ‘Shai-Hulud worm’ that had infected over 440 packages, including widely used libraries like keyv and flat-cache. This malware was designed to steal credentials such as GitHub tokens, SSH keys, and cloud access data by infiltrating development processes and CI/CD workflows.

Subsequent findings expanded the scope of the campaign, identifying nearly 800 malicious packages. The attack utilizes AI-generated or typo-squatted names to evade detection and deploys Remote Access Trojans (RAT) and infostealers. Research suggests North Korean-linked threat actors are involved, employing a sophisticated command-and-control mechanism that uses Ethereum transactions as a ‘public dead drop’ to retrieve infrastructure IP addresses, making the malware more resilient to traditional blocking methods.

Entities

npm · Sonatype · GitHub · Cybersense GmbH · Ethereum

Timeline

  1. 1 day ago

    [TECHNOLOGY] 5 sources
    npm registry targeted by massive malware campaign

    A major npm supply chain attack involving nearly 800 malicious packages has been discovered, with North Korean-linked actors using Ethereum transactions for stealthy command-and-control operations.

  2. 2 days ago

    [TECHNOLOGY] 2 sources
    Shai-Hulud worm targets npm ecosystem via supply chain attacks

    The Shai-Hulud worm has infected over 440 npm packages, including libraries with billions of monthly downloads, threatening global software supply chains by stealing developer credentials.

Sources

beachfest.co.il · cybersecuritynews.com · enterprisesecuritytech.com · fighthistory.com · it-daily.net · news-nachrichten.de · silobreaker.se