Laughing Hyena
  • Home
  • Hyena Games
  • Esports
  • NFT Gaming
  • Crypto Trends
  • Game Reviews
  • Game Updates
  • GameFi Guides
  • Shop
Tag:

Infected

Virus symbol, computer protection, cyber attack, antivirus, digital worm and bug icon. Futuristic abstract concept 3d rendering illustration.
Gaming Gear

A terrifying, self-replicating malwaere has infected npm packages with over 2 million downloads per week – here’s how to stay safe

by admin September 17, 2025



  • A new supply-chain attack compromised at least 187 npm packages, targeting developer secrets across software projects
  • Shai-Hulud worm looks to steal credentials, modify packages, and spread malware through GitHub Actions and npm tokens
  • Researchers warn the number of compromised packages is likely to grow

At least 187 malicious npm packages have been uncovered, part of a yet another major supply-chain attack against software developers.

Security researchers from Socket, StepSecurity, and Aikido all detected an ongoing campaign, apparently being orchestrated by the same group that targeted Nx several weeks ago.

Similar to that campaign, in this one the miscreants were also after developer secrets, including login credentials, AWS keys, GCP and Azure service credentials, GitHub personal access tokens, cloud metadata endpoints, or npm authentication tokens.


You may like

Many affected

However, the attack methodology evolved, the researchers noted.

“The scale, scope and impact of this attack is significant,” they explained. “The attackers are using the same playbook in large parts as the original attack, but have stepped up their game.”

This time around, the attackers created a worm, called Shai-Hulud (a nod to the Dune worm), which not only steals secrets and publishes them to GitHub publicly (using tools like TruffleHog and queries on cloud metadata endpoints), but also drops a malicious GitHub Action that sends secrets to an attacker-controlled webhook and hides them in logs, and uses stolen npm tokens to modify and republish every package the maintainer controls, embedding the worm in each one.

Among the compromised npm packages are those from cybersecurity experts CrowdStrike, as well as others with millions of weekly downloads.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

CrowdStrike, on its end, did what it could to mitigate the risk and minimize the damage.

“After detecting several malicious Node Package Manager (NPM) packages in the public NPM registry, a third-party open source repository, we swiftly removed them and proactively rotated our keys in public registries,” a CrowdStrike spokesperson said, The Register reports.

“These packages are not used in the Falcon sensor, the platform is not impacted and customers remain protected. We are working with NPM and conducting a thorough investigation.”

At the moment the number of packages affected by the attack sits at 187, the researchers warned that the number will most likely continue to rise. Some potentially compromised packages are currently pending validation.

Via The Register

You might also like



Source link

September 17, 2025 0 comments
0 FacebookTwitterPinterestEmail

Categories

  • Crypto Trends (1,098)
  • Esports (800)
  • Game Reviews (735)
  • Game Updates (906)
  • GameFi Guides (1,058)
  • Gaming Gear (960)
  • NFT Gaming (1,079)
  • Product Reviews (960)

Recent Posts

  • Voila! Nintendo quietly shares new details on Samus’s motorbike in Metroid Prime 4
  • Jimmy Fallon Is Trying To Make Wordle Into A Game Show
  • Marathon still lives, as Bungie announces new closed technical test ahead of public update
  • AirPods 4 Are Now 3x Cheaper Than AirPods Pro, Amazon Is Offering Entry-Level Clearance Prices
  • Wildgate Review – A Shipshape Space Race

Recent Posts

  • Voila! Nintendo quietly shares new details on Samus’s motorbike in Metroid Prime 4

    October 8, 2025
  • Jimmy Fallon Is Trying To Make Wordle Into A Game Show

    October 8, 2025
  • Marathon still lives, as Bungie announces new closed technical test ahead of public update

    October 8, 2025
  • AirPods 4 Are Now 3x Cheaper Than AirPods Pro, Amazon Is Offering Entry-Level Clearance Prices

    October 8, 2025
  • Wildgate Review – A Shipshape Space Race

    October 8, 2025

Newsletter

Subscribe my Newsletter for new blog posts, tips & new photos. Let's stay updated!

About me

Welcome to Laughinghyena.io, your ultimate destination for the latest in blockchain gaming and gaming products. We’re passionate about the future of gaming, where decentralized technology empowers players to own, trade, and thrive in virtual worlds.

Recent Posts

  • Voila! Nintendo quietly shares new details on Samus’s motorbike in Metroid Prime 4

    October 8, 2025
  • Jimmy Fallon Is Trying To Make Wordle Into A Game Show

    October 8, 2025

Newsletter

Subscribe my Newsletter for new blog posts, tips & new photos. Let's stay updated!

@2025 laughinghyena- All Right Reserved. Designed and Developed by Pro


Back To Top
Laughing Hyena
  • Home
  • Hyena Games
  • Esports
  • NFT Gaming
  • Crypto Trends
  • Game Reviews
  • Game Updates
  • GameFi Guides
  • Shop

Shopping Cart

Close

No products in the cart.

Close