Developers are advised to audit their environments and rotate npm tokens and other exposed secrets if the aforementioned packages are present with publishing credentials. More Than 500 Packages ImpactedThe ongoing npm supply chain incident, codenamed Shai-Hulud attack, has also leveraged the "crowdstrike-publisher" npm account to publish several trojanized packages. Supply chain security company ReversingLabs characterized the incident as a "first of its kind self-replicating worm" compromising npm packages with cloud token stealing malware. "Once infected by Shai-Hulud, npm packages spawn attacks of their own by unknowingly allowing the worm to self-propagate through the packages they maintain." "The most leaked secrets in this campaign are GitHub tokens, npm tokens, and AWS Keys," security researcher Gaetan Ferry said.