A compromised npm account (i@hust.cc) infected 314 npm packages with malware in a 22-minute window, hitting popular packages like size-sensor (4.2M monthly downloads), echarts-for-react (3.8M), and timeago.js. The malware — part of the ongoing Shai-Hulud campaign — steals credentials for GitHub, AWS, Azure, GCP, Docker, and Stripe from environment variables and files, exfiltrates them to attacker-controlled GitHub repos, and attempts container escapes. It also injects settings files targeting Claude Code and Codex for further execution. The attack used a stolen token for automation. Developers who installed affected versions should rotate all credentials, audit GitHub repos for unauthorized activity, and remove malicious systemd services. GitHub has responded with a statement about policy enforcement but has been criticized for limited action during the ongoing campaign.

3m read timeFrom devclass.com
Post cover image
Table of contents
Updated to add:
5 Impressions