Der GitHub-Account des Maintainers der Key-Value-Datenbank #keyv wurde kompromittiert Durch die Shai-Hulud-Lieferkettenattacke sind über 440 #npm-Pakete betroffen mit rund 2 Milliarden Downloads monatlich Der Schadcode startet automatisch bei Installation und sucht nach Zugangsdaten https://www.heise.de/news/Lieferketten-Angriff-auf-keyv-Shai-Hulud-Wurm-infiziert-mehr-als-440-npm-Pakete-11403078.html?seite=all
Sam Stepanyan
🐘
🐘
@securestep9@infosec.exchange
https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP
infosec.exchange
#npm: A massive #SupplyChain attack has compromised 868+ npm packages carrying 2 billion+ monthly installs with a credential-stealing worm.
It started with the compromise of the #GitHub account of the #keyv library with 127 million+ weekly downloads:
👇
https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack
Daily CyberSecurity
@DailyCyberSecurity@infosec.exchange
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
infosec.exchange
A new npm supply chain attack hijacked keyv and dozens of packages, spreading Shai-Hulud malware that steals cloud and CI/CD secrets. Rotate keys now.
#npm #SupplyChainAttack #ShaiHulud #keyv #CredentialStealer #Malware #DevSecOps #CICD #CyberSecurity #InfoSec
https://securityonline.info/npm-supply-chain-attack-keyv-shai-hulud/?utm_source=mastodon&utm_medium=jetpack_social
You've seen all posts