{"id":9088,"date":"2025-11-25T08:50:45","date_gmt":"2025-11-25T08:50:45","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=9088"},"modified":"2025-11-25T08:50:45","modified_gmt":"2025-11-25T08:50:45","slug":"shai-hulud-is-again-with-a-brand-new-marketing-campaign-infecting-extra-npm-packages","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=9088","title":{"rendered":"Shai-Hulud is again with a brand new marketing campaign infecting extra npm packages"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n                  <img width=\"490\" height=\"735\" class=\"alignright size-medium wp-post-image lazyload\" alt=\"\" decoding=\"async\" fetchpriority=\"high\" src=\"https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280-490x735.jpg\" srcset=\"https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280-490x735.jpg 490w, https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280-200x300.jpg 200w, https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280-682x1024.jpg 682w, https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280-100x150.jpg 100w, https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280-768x1152.jpg 768w, https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280-150x225.jpg 150w, https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280-53x80.jpg 53w, https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280-400x600.jpg 400w, https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280-120x180.jpg 120w, https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280-33x50.jpg 33w, https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280.jpg 853w\" data-sizes=\"auto\" data-eio-rwidth=\"490\" data-eio-rheight=\"735\"\/><img width=\"490\" height=\"735\" src=\"https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280-490x735.jpg\" class=\"alignright size-medium wp-post-image\" alt=\"\" decoding=\"async\" fetchpriority=\"high\" srcset=\"https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280-490x735.jpg 490w, https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280-200x300.jpg 200w, https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280-682x1024.jpg 682w, https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280-100x150.jpg 100w, https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280-768x1152.jpg 768w, https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280-150x225.jpg 150w, https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280-53x80.jpg 53w, https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280-400x600.jpg 400w, https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280-120x180.jpg 120w, https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280-33x50.jpg 33w, https:\/\/sdtimes.com\/wp-content\/uploads\/2025\/11\/desert-4134918_1280.jpg 853w\" sizes=\"(max-width: 490px) 100vw, 490px\" data-eio=\"l\"\/><\/p>\n<p>A brand new malicious marketing campaign linked to the Shai-Hulud worm is making its approach all through the npm ecosystem. Based on <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.wiz.io\/blog\/shai-hulud-2-0-ongoing-supply-chain-attack\">findings from Wiz<\/a>, over 25,000 npm packages have been compromised and over 350 customers have been impacted.<\/p>\n<p>Shai-Hulud was a worm that contaminated the npm registry <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/sdtimes.com\/security\/github-details-upcoming-changes-to-improve-security-in-wake-of-shai-hulud-worm-in-npm-ecosystem\/\">again in September<\/a>, and now a brand new worm spelled as Sha1-Hulud is showing within the ecosystem once more, although it&#8217;s unclear on the time of writing whether or not the 2 worms have been made by the identical menace actor.<\/p>\n<p>Wiz and Aikido researchers have confirmed that Sha1-Hulud was uploaded to the npm ecosystem between November twenty first and twenty third. In addition they say that tasks from Zapier, ENS Domains, PostHog, and Postman have been a few of the ones that have been trojanized, and newly compromised packages are nonetheless being found.<\/p>\n<p>Like Shai-Hulud, this new malware additionally steals developer secrets and techniques, although Garrett Calpouzos, principal safety researcher at Sonatype, defined that the mechanism is barely completely different, with two recordsdata as a substitute of 1. \u201cThe primary checks for and installs a non-standard \u2018bun\u2019 JavaScript runtime, after which makes use of bun to execute the precise relatively large malicious supply file that publishes stolen knowledge to .json recordsdata in a randomly named GitHub repository,\u201d he advised SD Instances.<\/p>\n<p>Wiz believes this preinstall-phase considerably will increase the blast radius throughout construct and runtime environments.<\/p>\n<p>Different variations, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.aikido.dev\/blog\/shai-hulud-strikes-again-hitting-zapier-ensdomains\">in keeping with Aikido<\/a>, are that it creates a repository of stolen knowledge with a random title as a substitute of a hardcoded title, can infect as much as 100 packages as a substitute of 20, and if it will probably\u2019t authenticate with GitHub or npm it wipes all recordsdata within the consumer\u2019s Residence listing.<\/p>\n<p>The researchers from Wiz advocate that builders take away and exchange compromised packages, rotate their secrets and techniques, audit their GitHub and CI\/CD environments, after which harden their pipelines by limiting lifecycle scripts in CI\/CD, limiting outbound community entry from construct programs, and utilizing short-lived scoped automation tokens.<\/p>\n<p>Sonatype\u2019s Calpouzos additionally stated that the dimensions and construction of the file confuses AI evaluation instruments as a result of it&#8217;s larger than the traditional context window, making it laborious for LLMs to maintain monitor of what they&#8217;re studying. He defined that he examined this out by asking ChatGPT and Gemini to investigate it, and has been getting completely different outcomes each time. It&#8217;s because the fashions are looking for apparent malware patterns, reminiscent of calls to suspicious domains, and aren\u2019t discovering any, resulting in the conclusion that the recordsdata are reliable.<\/p>\n<p>\u201cIt\u2019s a intelligent evolution. The attackers aren\u2019t simply hiding from people, they\u2019re studying to cover from machines too,\u201d Calpouzos stated.<\/p>\n<\/p><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>A brand new malicious marketing campaign linked to the Shai-Hulud worm is making its approach all through the npm ecosystem. Based on findings from Wiz, over 25,000 npm packages have been compromised and over 350 customers have been impacted. Shai-Hulud was a worm that contaminated the npm registry again in September, and now a brand [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":9090,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[396,5395,1116,2987,5393],"class_list":["post-9088","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-software","tag-campaign","tag-infecting","tag-npm","tag-packages","tag-shaihulud"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/9088","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9088"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/9088\/revisions"}],"predecessor-version":[{"id":9089,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/9088\/revisions\/9089"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/9090"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9088"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9088"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9088"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-05-06 16:56:06 UTC -->