HomeSecurityNew version of Shai-Hulud worm spreads via npm, GitHub

New version of Shai-Hulud worm spreads via npm, GitHub

A new version of the self-propagating credential-stealing worm Shai-Hulud is spreading via the open npm registry .

 Shai-Hulud worm npm, GitHub

Researchers at Wiz Inc.reported that in the early stages of the campaign, late last week, a thousand new GitHub repositories containing victim data were being uploaded every 30 minutes. Researchers at JFrog identified 181 compromised packages.

The current campaign introduces a new variant, which Wiz researchers call Shai-Hulud 2.0. This one executes malicious code during the pre-installation phase, “significantly increasing potential exposure in build and execution environments.”

The threat exploits compromised package maintainer accounts to publish modified versions of legitimate npm. Once installed, the malware exports developer and CI/CD secrets to GitHub repositories and injects the malicious payload into all of the users' available npm packages. Malicious users could also use the exported secrets to infiltrate and install more malware on victims' IT systems.

JFrog said that this new variant generates random repository names for extraction, making it harder for security teams to detect and clean up leaked secrets. JFrog also said that the new payload contains new features, such as privilege escalation, DNS hijacking, and the ability to delete data from the victim's machine.

See also: APT group ToddyCat gains access to internal employee communications

Many popular packages used by developers, including those from Zapier, ENS Domains, PostHog, and Postman, have been compromised.

ReversingLabs researchers also noted that the list of compromised packages includes packages related to AsyncAPI , including @asyncapi/specs , which has over 100 million downloads (and an average of 1.4 million downloads per week). This package is also believed to be the “ patient-zero ,” or first known infected package, for this wave of attacks.

New version of Shai-Hulud worm spreads via npm, GitHub

Shai-Hulud 2.0: Second largest and fastest wave of infections

Developers and security teams looking for indicators of compromise should note that the new variant adds two new payload files: setup_bun.js and bun_environment.js.

“The worm’s resurgence suggests that it remains a current and serious threat to the npm ecosystem,” said Johannes Ullrich, dean of research at the SANS Institute. “CSOs should address this threat by monitoring the assets used in their software and strengthening their CI/CD pipelines to increase resilience in the event that malicious code is executed.”

Shai-Hulud first appeared in September, affecting dozens of npm libraries, including a color library with over 2 million downloads per week. The libraries were replaced with malicious versions.

The initial Shai-Hulud wave was already one of the most serious JavaScript supply chain attacks Wiz has seen.

See also: Hackers steal customer data from JPMorgan Chase and Citi

“This new wave is bigger and faster: more than 25,000 repositories, created by attackers on about 350 GitHub users, are growing by about 1,000 repositories every 30 minutes. The malware steals developer and cloud credentials and executes in the pre-installation phase, touching dev machines and CI/CD pipelines. This combination of scale, speed, and access makes it a high-impact campaign,” the researcher said.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

New version of Shai-Hulud worm spreads via npm, GitHub

Breach is almost certain

If anyone had downloaded any of the affected packages between November 21-23, they should assume their environment is exposed. Solutions include clearing the npm cache on their workstation, removing node_modules, reinstalling from clean builds , or sticking to builds released before the malicious builds. It is also recommended to rotate any tokens or secrets that may have been present (GitHub PATs, npm tokens, SSH keys, cloud credentials).

Enabling strong MFA on GitHub/npm and monitoring for unexpected new repositories or workflow files in the developer's personal account is also critical.

Recommendations for repositories

To prevent attackers from easily uploading malicious packages, npm needs to make the publishing process and ensure that the identity of new accounts is verified before they are allowed to publish packages.

Also, new rate limits should be implemented to prevent attackers from uploading multiple malicious packages in a short period of time and to monitor package maintainers for suspicious activity (such as sudden increases in publishing or packages with significant unexplained changes).

See also: Hackers replace the letter 'm' with the combination 'rn' in Microsoft

In this context, it is most important to continue to strengthen the guardrails around how are published and packages. This includes making it harder for compromised maintainer accounts to push malicious releases, increasing visibility into unusual publishing behavior, and helping users quickly understand when a package version may be unsafe.

These are ecosystem-wide defenses and not criticisms of any individual registry, but they reflect the direction the entire open source community should be moving in as attacks like Shai-Hulud become more automated and widespread.

Ensar Seker, CISO at SOCRadar, warned that Shai-Hulud is not what you would call a typical package breach. “It’s a worm embedded in the development supply chain. It means that attackers are shifting from targeting compiled binaries and runtime environments to the very processes that developers use to build and ship software. No organization should assume ‘We don’t use npm, so we’re safe,’ because even downstream dependencies or dev toolchains can become the starting point”.

New version of Shai-Hulud worm spreads via npm, GitHub

So far, npm has focused on ensuring that package authors are properly authenticated and that packages are not modified after publication, said Ullrich of the SANS Institute. But, he added, that doesn't stop a malicious user from publishing malicious packages. Recently, npm further limited the default access token lifetimes and began revoking the old "classic tokens."

«npm may need to implement some form of automated scanning for obvious malicious content, but a meaningful solution will be difficult to implement».

See also: Wireshark vulnerabilities allow system crash

Recommendations for security teams, developers

Wiz says that security teams in organizations using npm – and individual developers using npm and GitHub – should: clear cache , stick to known clean dependency versions or revert to versions before November 21, revoke and generate new npm tokens, GitHub PATs, SSH keys, and cloud provider, enforce phishing-resistant multi-factor authentication for developer accounts and CI/CD (continuous integration/continuous delivery).

In GitHub and CI/CD environments, they should look for newly created repositories with the description 'Shai-Hulud', examine unauthorized workflows or suspicious commits that mention hulud, and monitor for new npm releases under their organization. C

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS