• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages

Admin by Admin
August 5, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


A quick-moving software program supply-chain assault has compromised Keyv and lots of of different npm packages, exposing developer workstations and steady integration techniques to credential-stealing malware. Aikido Safety recognized the malware as a Shai-Hulud variant, following earlier campaigns reported by Hackread.com in 2025.

Aikido traced the preliminary assault to the GitHub account of developer Jared Wray, maintainer of Keyv, a key-value storage library receiving roughly 127 million weekly npm downloads. Attackers pushed malicious recordsdata on to the principle department and used the legit GitHub Actions launch course of to publish Keyv model 6.0.0.

As a result of the poisoned launch handed via the challenge’s regular publishing workflow, it carried legitimate provenance data on npm. The signature verified the place the bundle was constructed, however not whether or not the supply code getting into that course of was secure.

How the Assault Works

The primary poisoned releases recognized in Wray’s bundle household included Keyv, flat-cache, file-entry-cache, cacheable-request, cacheable, cache-manager, @cacheable/reminiscence, @cacheable/node-cache, @cacheable/utils, @cacheable/web, and ecto.

Every launch contained two added recordsdata named setup.mjs and Math_Symbol.js. Attackers additionally inserted the next lifecycle command into bundle.json:

"preinstall": "node setup.mjs"

On npm shoppers that let dependency lifecycle scripts, putting in an affected model causes setup.mjs to execute earlier than set up finishes. Nonetheless, npm 12 blocks unapproved dependency set up scripts by default, so the payload doesn’t run routinely below each npm configuration.

As soon as executed, setup.mjs downloads Bun model 1.3.13 from its official GitHub launch web page and makes use of it to launch Math_Symbol.js. The closely obfuscated 728 KB payload searches for npm authentication tokens, GitHub credentials, AWS keys, Kubernetes secrets and techniques, HashiCorp Vault tokens, non-public keys, database credentials, and tokens belonging to companies corresponding to Stripe and Slack.

After accumulating the knowledge, the malware encrypts it and uploads it to a public GitHub repository whose description incorporates “Shai-Hulud: Right here We Go Once more.” If that add fails, it might probably ship the stolen information to npm-cache(.)com.

Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages
Screenshot by way of Aikido Safety

Worm Reaches Packages Linked to Main Firms

By its 13:37 CEST replace, Aikido reported no less than 868 affected packages involving 1,381 malicious variations. Collectively, these packages obtain greater than two billion month-to-month downloads. The determine describes their mixed regular obtain quantity, not two billion contaminated units or confirmed malware executions.

Utilizing stolen npm and GitHub credentials, the worm modifies and republishes packages out there to different maintainers. Aikido researcher Charlie Eriksen later reported that fifty to 100 extra packages had been showing each couple of minutes, with the noticed depend passing 1,280.

Packages linked to Deliveroo, OneReach, ServiceTitan, Picsart and Qlik appeared within the marketing campaign. Examples included:

  • @deliveroo/reevent model 1.0.1
  • @or-sdk/invites model 1.4.9
  • @picsart/ai-sdk model 3.32.2
  • @qlik/embed-runtime model 1.6.4
  • picasso.js model 2.11.6

Their presence exhibits that bundle publishing entry related to these names was abused. It doesn’t set up that the businesses’ inner networks had been breached.

What Improvement Groups Ought to Do

Any workstation or CI runner that executed an affected model must be handled as credential-exposed. Eradicating the bundle alone won’t invalidate credentials already collected by the malware.

Improvement groups ought to examine lockfiles for actual bundle variations, take away affected releases, rotate npm, GitHub, cloud, and Vault credentials, look at repositories for unauthorized commits, and assessment cloud logs for surprising entry. Aikido has additionally suggested prospects to set off an instantaneous handbook rescan as an alternative of ready for the corporate’s nightly scan.



Tags: npmPackagespoisoningReturnsShaihuludWorm
Admin

Admin

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

The right way to use Netdiscover to map and troubleshoot networks

The right way to use Netdiscover to map and troubleshoot networks

August 26, 2025
Learn how to Develop an App Like Uber in 2026

Learn how to Develop an App Like Uber in 2026

May 8, 2026
Why Your Web site is Failing to Convert—and How a Net App Can Save the Day

Why Your Web site is Failing to Convert—and How a Net App Can Save the Day

April 2, 2025
The Visible Haystacks Benchmark! – The Berkeley Synthetic Intelligence Analysis Weblog

The Visible Haystacks Benchmark! – The Berkeley Synthetic Intelligence Analysis Weblog

May 2, 2025
AI Pioneers Win Nobel Prizes for Physics and Chemistry

AI Pioneers Win Nobel Prizes for Physics and Chemistry

May 19, 2025

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages

Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages

August 5, 2026
Hearth Emblem: Fortune’s Weave – Every little thing We Simply Discovered From The Direct

Hearth Emblem: Fortune’s Weave – Every little thing We Simply Discovered From The Direct

August 4, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved