6 ms·
Keyv and friends compromised in active Shai-Hulud supply chain attack
- avaer 2mo agoI am kind of surprised GitHub doesn't seem to have built a simple classifier for public repos to proactively lock the account of anyone uploading such obviously fishy things (for their own good, at least before the repo is publicly findable), so it can't be used as a rendezvous. Surely Github's software is good enough that an intern can slop the 80/20 together in a day? It would be an actually good use of AI spending.
- hulitu 2mo ago> I am kind of surprised GitHub doesn't seem to have built a simple classifier for public repos to proactively lock the account of anyone uploading such obviously fishy things (for their own good, at least before the repo is publicly findable), so it can't be used as a rendezvous. Maybe that's the idea. Regards, the <insert your favourite 3 letter agency here>
- abhisek 2mo agoGitHub announced this a while back: https://github.blog/changelog/2026-07-28-npm-publish-time-malware-scanning-and-dual-use-metadata/ https://github.blog/changelog/2026-07-28-npm-publish-time-ma...
- drakythe 2mo ago"A while back" -- One week ago. I am curious if they are still implementing the process or if this particular attacker already figured out a way around it.
- twistedpair 2mo agoAh, I see your problem there > This requirement will be progressively enforced over time.
- vlovich123 2mo ago> Update — August 4, 2026, 13:37 CEST: At least 868 packages (across 1381 versions) have been compromised by the worm, with a combined total of over 2 billion monthly installs at the time of writing. This is such lazy or click baiting writing. Who cares how many installations there are per month normally? The high install numbers are almost certainly from running in CI where such secrets don’t exist. How many installs actually occur in a non CI environment and of those how many were the compromised version?
- insanitybit 2mo ago> almost certainly from running in CI where such secrets don’t exist. CI usually has the most privileged secrets anywhere in a company lol
- TeMPOraL 2mo agoCIs having per-package installs : version ratio > 1 are fundamentally dumb idea in the first place. In a way, this teaches us that there is something as too much reliability in an ecosystem. Specifically, Github is apparently reliable enough that its occasional outages are insufficient to kill all the companies running these dumb CI setups that redownload packages from the Internet every build - so there's no incentive to reduce waste and improve security globally.
- rcxdude 2mo agoRedownloading and automatically updating to the new version are pretty orthogonal. You can have a solution which caches the packages but would still update to a new version or a solution which redownloads the (verifiably) same package each time. Vendoring libraries stops both but it's the automatic updates which are the biggest risk factor.
- cookiengineer 2mo ago> CI usually has the most privileged secrets anywhere in a company lol Literally the reason the stealer of Miasma was focusing on extracting tokens from the CI/CD runner from the start.
- xnorswap 2mo agoAt this point, any package adding a pre-install hook where there previously was not one should be denied and treated with extreme suspicion. It's time pre-install / post-install hooks were killed off. Start with a moratorium on any new ones.
- mechazawa 2mo agoiirc does pnpm not allow them by default. But even if we killed them off there would still be a chance of the malware hooking into something else or only working in cli applications.
- jonchurch_ 2mo agonpm v12 released last month also defaults into blocking them by default
- madeofpalk 2mo agoThe latest version of all node package managers (npm, yarn, pnpm) now deny this by default. pnpm was ahead of the curve.
- jitl 2mo agoyeah but they can just put the dropper, etc in index.js, so that it runs at import time rather than at install time, no? i guess first-install time is often a privileged developer machine, and will execute in a "server"-like runtime such as Node, Bun, Deno. but blocking preinstall scripts is basic first aid...
- jerf 2mo agoNobody is claiming this is a complete solution to security. I would call this "necessary but not sufficient". You won't get far as an engineer if you refuse to implement "necessary but not sufficient" changes because the change doesn't in and of itself one-shot the entire problem.
- 2mo ago
- ftlps 2mo agoaikido.dev: SAST, AI code analysis and therefore a website that uses 100% CPU and prevents scrolling. To the point of the article: I don't know why GitHub still allows the release feature. It is complete insanity. Tar archives must be constructed manually and checked for leaked keys etc.
- tgv 2mo agoI got the news via https://safedep.io/keyv-npm-supply-chain-compromise/ https://safedep.io/keyv-npm-supply-chain-compromise/
- mittermayr 2mo agoDoes anyone happen to have a grep or similar that helps me check if this is showing up anywhere in the trillions of files in node_modules (or pnpm store)?
- rhdunn 2mo agoThe what happened section mentions the addition of the `setup.mjs` and `Math_Symbol.js`, along with a change in `package.json` to add `"preinstall": "node setup.mjs"`, so presumably checking for any of those would be a good indication to check further. For example: find . -type f | grep -P "/Math_Symbol\.js$"
- yread 2mo agoCrucially, Math_Symbol.js that is almost 800KB, not the innocent 1KB one from regenerate-unicode-properties
- somebudyelse 2mo agowhen i was searching i got a heartattack when i saw Math_Symbol.js. Thankfully my agent was able to figure it out.
- orheep 2mo agofind . -type d -name node_modules -prune -exec find {} \( -name setup.mjs -o -name math_init.js -o -name Math_Symbol.js \) \; 2>/dev/null
- byutifu 2mo agoThis article has a lot of information and ways to check & clean: https://safedep.io/keyv-npm-supply-chain-compromise/ https://safedep.io/keyv-npm-supply-chain-compromise/
- somebudyelse 2mo agoI ended up asking my agent with auto mode: can you search all installed node modules for any sign of the shai hulud supply chain attack? What happened Every package in the family received two new files, setup.mjs and Math_Symbol.js, along with a "preinstall": "node setup.mjs" entry added to each package.json. Anyone who ran npm install against an affected version would have had setup.mjs execute automatically before their install completed. setup.mjs is a heavily obfuscated dropper. Its only job is to silently download the Bun JavaScript runtime from github[.]com/oven-sh/bun/releases/download/bun-v1.3.13/ and use it to execute the real payload, Math_Symbol.js: execFileSync(<bun binary>, ['<script_dir>/Math_Symbol.js'], { stdio: 'inherit', cwd: <script_dir> }) The Math_Symbol.js is a heavily obfuscated 728 KB JavaScript file containing credential stealers that harvest secrets from the victim's environment, encrypt the findings, and exfiltrate them to a public GitHub repository whose description reads "Shai-Hulud: Here We Go Again". The payload also contains worm-like propagation functionality to infect packages of other maintainers that have installed one of the compromised packages.
- cute_boi 2mo agoI think npm can use chatgpt/claude for each published package to detect these types of attack? And if it sees they can restrict the package from making any changes.
- codeduck 2mo agoOh boy, it's a big one.
- TacticalCoder 2mo ago> Oh boy, it's a big one. Yup the "Update" in TFA is scary: "Update — August 4, 2026, 13:37 CEST: At least 434 packages (across 1381 versions) have been compromised by the worm, with a combined total of over 2 billion monthly installs at the time of writing." Lots of pain ahead.
- somebudyelse 2mo agothe irony of the update being at 1337
- twistedpair 2mo ago2,523 and counting
- ethanwillis 2mo agoYou know with all this AGI swirling around nowadays that is stronger than nation state hackers you think one of these companies would demonstrate just how capable they are by defending public infrastructure. Unless... Maybe in 6 months.
- pixl97 2mo agoLLMs are better at attacking than writing secure code. LLMs aren't terrible at securing systems, humans are bad at using secure systems and typically disable measures with insecure workarounds.
- thinkingemoji 2mo agoNo way to prevent this says only package manager where this regularly happens
- insanitybit 2mo agoThis is the most boring comment posted on every one of these. NPM is by no means the worst offender here and offers a ton of solutions to this, lots of package managers are behind it or equivalent. NPM gets targeted a lot because it's popular. That's it.
- walrus01 2mo agoOther than what happened with 'xz', which was upstream of it getting packaged, how many times has this happened in the debian packages system? Also very popular.
- insanitybit 2mo agoI don't consider these comparable in any way that's worthwhile. The scale and goals are completely different.
- walrus01 2mo agoHow are they not comparable?
- insanitybit 2mo agoDebian's scale for package distribution is tiny and explicitly curated by maintainers. Everything funnels through Debian. The goals are completely different. Debian packages what's necessary for an OS, npm packages everything needed for any projects arbitrarily. Auditing scales to one of those, not the other.
- walrus01 2mo ago
- Catloafdev 2mo agoI mean what are these devs doing that they are day-1 updating npm packages still? How many instances of this are required before npm package maintainers learn?
- daniel_mcsoft 2mo agoThe cheapest mitigation almost nobody deploys: a version cooldown. These worms get caught fast — this one was flagged same-day, and the article's own timeline shows detection racing ahead of spread. If your CI simply refuses to adopt any version published in the last N days (Renovate supports this natively via minimumReleaseAge), you convert "worm spreads through the ecosystem in hours" into "worm must survive N days of public scrutiny before it can reach you." You give up almost nothing: how often does your product genuinely need a dependency version that's 48 hours old? Combine that with the workflow split insanitybit describes — build/test jobs holding zero publish credentials, a separate publish job that only touches a finished artifact — and the wormable path is mostly closed without waiting for npm to redesign itself. None of this is "sufficient" in rcxdude's sense, and that's fine. Sufficiency isn't the bar during an active outbreak; raising the attacker's cost per hop is.
- freakynit 2mo agoFirst point.. plus, OTP/MFA authenticated publishing. This OTP/MFA should come from package repositories, before the package is made publicly available. This is needed so that CD stage is not blocked. OTP/MFA should be scoped to publishing user/org, not the package. How the OTP/MFA client is managed across the maintainers/org, lies in the scope of maintainers/org.
- pixl97 2mo agoThis still does nothing to prevent anyone from publishing a bad package, for example a compromised device/dev in the organization. A cooldown of a day, and maybe not updating on weekends will save you from that. It's time to stop moving at the speed of stupid.
- deleted 2mo ago[deleted]
- bijowo1676 2mo agoI have a suspicion that a lot of these supply chain compromises are done by the security researchers at security vendors, selling software to protect the software supply chain. Spreading fear to create demand for their products. Like in the good ole days of Windows 98 and antivirus era, a lot of advanced virus techniques in the wild came from the people who used to work for AV companies
- woodruffw 2mo agoThat would be extremely surprising, given the number and severity of federal crimes involved. (I also dare say: many of these attackers demonstrate a better in-depth understanding of packaging ecosystems than supply chain security vendors do.)
- bijowo1676 2mo agothe federal crimes part is irrelevant if its below the threshold of federal authorities actually cracking down on them and figuring out entire chain. just because credit card theft and other types of scam are illegal I remember how ddos attackers created "DDOS protection" companies to protect their victims against DDOS.
- woodruffw 2mo agoI don’t think the impact of these recent malware campaigns is below the threshold for federal interest.
- Fnoord 2mo agoThat is not a suspicion, but a (baseless) theory. I mean, your proof is from Windows 98. Might as well been an outlier or urban legend, who knows. My theory is that people in countries without extradition laws to USA are going to spray the shit out of Americans. With spam, and crap like this worm, troll farms, and the like. Also baseless, but people who work at SOC can notice an increase since some changes happened in geopolitics this decade.
- cadamsdotcom 2mo ago
- ChrisMarshallNY 2mo agoOW. That's gonna leave a mark. It sucks that we have this glass-jaw dependency system, which is really the main reason these supply chain attacks work. Really hard to clean up, too. These days, you (being the blackhat) would likely send agents to leverage every compromised repo/app/Web site, almost the instant it comes online, so even if the original mess is cleaned up, there's still a ton of knock-on compromises.
- varunsharma07 2mo agoWe (StepSecurity) published a full analysis of both payload stages: https://www.stepsecurity.io/blog/chaindrop-npm-worm https://www.stepsecurity.io/blog/chaindrop-npm-worm Some additional detail from our analysis: 1. Provenance did not fail, it worked as designed and still shipped malware. The initial 11 packages were published through npm OIDC Trusted Publishing with valid SLSA attestations. The attacker compromised the maintainer's GitHub account and let the projects' own release workflows publish. Provenance proves which commit was built, not that the commit was authorized. 2. There is a booby trap on remediation: the worm installs a watcher that fires an attacker payload when the stolen GitHub token gets revoked. Remove the token monitor first, then rotate. 3. Persistence goes beyond node_modules. It writes .claude/settings.json (SessionStart hook) and .vscode/tasks.json (runOn: folderOpen), each re-executing the dropper. Check repo dotfiles too. 4. No C2 domain to sinkhole: exfil endpoints resolve at runtime from an Ethereum contract. Observed domain is npm-cache.com, but the operator can rotate it and push new code to infected hosts. If you're auditing: look for setup.mjs, a 727,680 byte Math_Symbol.js (math_init.js in the second wave), and "preinstall": "node setup.mjs" in package.json. Careful, regenerate-unicode-properties ships a legitimate 1 KB Math_Symbol.js; the malicious one is over 700 KB. Full IOC and package list in the post, updated as the campaign develops.
- nubg 2mo agoai slop comment. post the original prompt
- jesse_dot_id 2mo agoecho "min-release-age=5" >> ~/.npmrc This should be your default minimum if you work with node.
- nubg 2mo agoad slop post
- evertheylen 2mo agoOnce again, I ask myself: should we start "shaming" developers who don't use isolation? It still seems I am the exception and most people run their dev environment with full permissions. Why? I also wrote an article (https://evertheylen.eu/p/shame-devs-without-isolation/ https://evertheylen.eu/p/shame-devs-without-isolation/) to flesh out my thoughts, but I'd be really happy to discuss this in the comments.
- vhcr 2mo agoYes, it gets boring that each time one of these supply chain attack article appears everybody starts talking about cooldowns, 2FA, MFA, etc. Just don't give Node the permissions to your complete filesystem / network.
- acdha 2mo agoI think it’s premature before a lot of tools improve to make that more workable: for example, if you use AWS how realistic is maintain separate IAM for each tool you run and map the right one into a sandbox for each tool? To use your editor’s GitHub integration with a token which can do basic operations and only retrieves a high-privilege token with a hardware presence check when you cut a release? Theoretically you can do it but the friction is enough to make it non-viable.
- evertheylen 2mo agoCould you not use something like https://github.com/superfly/tokenizer https://github.com/superfly/tokenizer for AWS? They list it as an explicit example, but I have little experience with AWS.
- acdha 2mo agoPossibly, but my point was basically that I wouldn’t be judgey about developers not doing something which most tools aren’t designed to make easy, or even possible. We absolutely should be trying to get to the point where it’s easy - this is like software deployment before containers and shouldn’t be.
- freakynit 2mo agoUpdated my docs covering these attacks since 2025: 1. NPM Supply Chain Attack Techniques: https://npm-supply-chain-attack-techniques.pagey.site/ https://npm-supply-chain-attack-techniques.pagey.site/ 2. NPM Ecosystem Threat Report: https://npm-supply-chain-attacks-25-26.pagey.site/ https://npm-supply-chain-attacks-25-26.pagey.site/
- khanhnguyen8386 2mo ago[flagged]
- tomjen3 2mo agoWhere is the fbi in this? Why has no one been arrested? This is a massive crime.
- egonschiele 2mo agoI'm guessing (though not sure) the actors are outside the US.
- cookiengineer 2mo agoFBI has no jurisdiction over Russia. And Russia doesn't give a damn, as they literally gave APT28/29 the mandate to do this, the only exception being that no former Sovjet territories can be attacked. (With the current exception of Ukraine ofc).
- atechboy 2mo agowhat commercial tools are enterprises using today to defend against such attacks? Do they really work? I mean, do they report/block malware after the fact or detect proactively. Because if the latter then, package registries should really be removing reported packages, right?
- phyzome 2mo agoCouldn't GitHub detect a Shai-Hulud exfil repo being created and just... block it? Given that it's a worm, the attacker wouldn't be able to adapt all that quickly.
- richbell 2mo agoIt's baffling that this hasn't been done after the 6th(?) time in the past year.
- cookiengineer 2mo agoWe're talking about Microsoft, who created a notepad.exe that can run an RCE with an LLM bypass prompt. In the previous Miasma waves, Microsoft was so overwhelmed that they delayed the VSCode extension installs for a couple days with a timeout; literally not understanding what was going on and neither how the malware was spreading.
- trueno 2mo agomicrosoft those dudes are hilarious this decade plus old github request is the only one i've ever gotten email alerts for it just made me lmao more each and every year. someone dropped a cake on its tenth birthday https://github.com/microsoft/vscode/issues/519#issuecomment-5151597222 https://github.com/microsoft/vscode/issues/519#issuecomment-...
- TimJRobinson 2mo agoIt's time for all developers to learn about devcontainers and use them consistently. They're super easy to setup and run and would protect from most of what this worm does. https://code.visualstudio.com/docs/devcontainers/containers https://code.visualstudio.com/docs/devcontainers/containers is the best guide to get started if you use vscode.
- acdha 2mo agoThey help only to the extent that you have completely isolated credentials: the hard part isn’t the container, it’s things like fastidiously using separate least-privilege credentials everywhere and not using tools or editor integrations which don’t support that style of work. Once you map your GitHub or AWS token into a container, it’s no longer useful as a security boundary.
- ashishbijlani 2mo agoI've been building an OSS tool to detect software supply-chain attacks: https://github.com/ossillate-inc/packj https://github.com/ossillate-inc/packj Packj uses static+dynamic code/behavioral analysis to scan for indicators of compromise (e.g., spawning of shell, use of SSH keys, network communication, use of decode+eval, etc). It also checks for several metadata attributes to detect impersonating packages (typo squatting).
- koalak 2mo ago[dead]
- reindeer2 2mo ago[flagged]
- cookiengineer 2mo agoyawns Good morning world, Here's the updated Antimiasma tool for mitigation [1] [2]. More details on how this tool was built and how the Miasma worm works on my website [3]. This is the first false flag in the campaign series, where setting the "LANG" environment variable to "ru_RU.UTF-8" or "ru_RU.KOI8-R" won't stop the spreading mechanism. So it's likely this could've been any script kiddie that modified the TeamPCP source code dump. It could now also be still APT28/29, that was kind of the purpose of the code dump... to gain plausible deniability :) Anyways, stay safe folks. [1] https://github.com/cookiengineer/antimiasma https://github.com/cookiengineer/antimiasma [2] https://github.com/cookiengineer/antimiasma/releases/tag/miasma-here-we-go-again https://github.com/cookiengineer/antimiasma/releases/tag/mia... [3] https://cookie.engineer/projects/cyber-defense/antimiasma.html https://cookie.engineer/projects/cyber-defense/antimiasma.ht...
- michaelksaleme 2mo ago[flagged]
- FacelessAICoder 2mo ago[flagged]