None
EN
Self-Replicating Worm Hits 180+ Software Packages
[]
Krebs on Security
The malware, which briefly infected multiple code packages from the security vendor CrowdStrike, steals and publishes even more credentials every time an infected package is installed.
The Shai-Hulud worm emerged just days after unknown attackers launched a broad phishing campaign that spoofed NPM and asked developers to “update” their multi-factor authentication login options.
That attack led to malware being inserted into at least two-dozen NPM code packages, but the outbreak was quickly contained and was narrowly focused on siphoning cryptocurrency payments.
He said the first NPM package compromised by this worm appears to have been altered on Sept. 14, around 17:58 UTC.
The security-focused code development platform socket.dev reports the Shai-Halud attack briefly compromised at least 25 NPM code packages managed by CrowdStrike.
['credentials'
'shaihulud'
'code'
'worm'
'compromised'
'hits'
'npm'
'attack'
'package'
'software'
'security'
'selfreplicating'
'krebs'
'packages'
'malware'
'180']