Massive supply-chain attack compromises 440 packages under four hours

Massive supply-chain attack compromises 440 packages under four hours
An attacker compromised a GitHub maintainer account and used a self-replicating Mini Shai-Hulud variant to inject malicious code into more than 440 npm packages in under four hours, quickly expanding the blast radius to over 860 packages. The malware stole sensitive credentials and data from npm, GitHub, AWS, CI systems, AI configuration files, and cryptocurrency wallets, with researchers linking the campaign to patterns seen in TeamPCP activity. #MiniShaiHulud #TeamPCP #keyv #flat-cache #file-entry-cache

Keypoints

  • A GitHub maintainer account was compromised to launch the attack.
  • More than 440 npm packages were infected in less than four hours.
  • The worm began in keyv and spread through other packages managed by the same maintainer.
  • Over 860 packages with more than 2 billion monthly installs were affected.
  • The malware stole npm, GitHub, AWS, CI, AI configuration, and wallet credentials.

Read More: https://cyberscoop.com/supply-chain-attack-malware-mini-shai-hulud-teampcp/