#shaihulud

4 posts · Last used 10d

Back to Timeline
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Aug 04, 2026
A new npm supply chain attack hijacked keyv and dozens of packages, spreading Shai-Hulud malware that steals cloud and CI/CD secrets. Rotate keys now. #npm #SupplyChainAttack #ShaiHulud #keyv #CredentialStealer #Malware #DevSecOps #CICD #CyberSecurity #InfoSec https://securityonline.info/npm-supply-chain-attack-keyv-shai-hulud/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
hasamba @hasamba@infosec.exchange · Jul 20, 2026

🎯 Threat Intelligence

🔹 npm Supply Chain Escalation: From Shai-Hulud to Miasma RAT

Unit 42's updated report documents a sharp escalation in npm supply chain attacks following the Shai-Hulud worm in September 2025. The worm automated compromise and redistribution of malicious packages, shifting npm attacks from isolated typosquatting to systematic, weaponized campaigns.

🔹 Campaign Timeline

April 2026: Two campaigns identified. "Shai-Hulud: The Third Coming" started April 22. "Mini Shai-Hulud" began April 29.

May 2026: TeamPCP continued the Mini Shai-Hulud campaign with two new waves. One introduced a credential-free initial access technique. The other generated the highest single-hour package count of any Shai-Hulud worm to date. Copycat activity has since complicated attribution.

June 2026: At least 32 packages under the @redhat-cloud-services npm namespace were compromised. The attacker bypassed code review entirely and pushed a payload named Miasma.

July 2026: Attackers compromised release pipelines of four core AsyncAPI GitHub repositories on July 14. The campaign, calling itself miasma-train-p1, published five trojanized packages: • @asyncapi/generator@3.3.1 • @asyncapi/specs@6.11.2 • @asyncapi/specs@6.11.2-alpha.1 • @asyncapi/generator-helpers@1.1.1 • @asyncapi/generator-components@0.7.1

The payload is assessed as a descendant of the Miasma RAT.

🔹 Core TTP Shifts

  1. Wormable propagation: Payloads steal npm tokens and GitHub PATs to automatically infect and republish legitimate packages, as seen in the March 2026 Axios compromise.

  2. Infrastructure-level persistence: Attackers embed into CI/CD pipelines for long-term, undetectable access to enterprise environments.

  3. Multi-stage payloads: Dormant sleeper dependencies activate only under specific environmental conditions, evading automated scanners.

🔹 Attack Chain • Initial Access: Credential-free techniques, stolen npm tokens, GitHub PATs • Persistence: CI/CD pipeline compromise • Execution: Miasma RAT and descendants • Propagation: Automated republishing of trojanized packages • Evasion: Sleeper dependencies with conditional activation

Monitor for campaign identifiers "miasma-train-p1" and "Shai-Hulud: The Third Coming" in infrastructure logs.

🔹 npm #SupplyChain #ShaiHulud #MiasmaRAT #ThreatIntelligence

🔗 Source: https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/?utm_campaign=u42+research-EN_nmpsupplychainattacks-x

0
0
0
heise Security @heisec@social.heise.de · Jul 08, 2026
„Passwort“ Folge 61: News von Bombenbauwürmern bis Zertifikatskettenkomplexität Malware mit Anleitungen zum Bau von Atomwaffen ist eine beunruhigende Entwicklung. Auch die PKI kommt nicht zu kurz – und es gibt gute Nachrichten von Android. https://www.heise.de/news/Passwort-Folge-61-News-von-Bombenbauwuermern-bis-Zertifikatskettenkomplexitaet-11348471.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon #Android #IT #Journal #Sprachverarbeitung #Microsoft #Microsoft #PasswortPodcast #Podcast #Security #ShaiHulud #news
0
0
4
Netzpalaver @Netzpalaver@social.tchncs.de · Jun 14, 2026
0
0
0

You've seen all posts