Close Menu
SkytikSkytik

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    At Least 32 People Dead After a Mine Bridge Collapsed Due to Overcrowding

    November 17, 2025

    Here’s how I turned a Raspberry Pi into an in-car media server

    November 17, 2025

    Beloved SF cat’s death fuels Waymo criticism

    November 17, 2025
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    SkytikSkytik
    • Home
    • AI Tools
    • Online Tools
    • Tech News
    • Guides
    • Reviews
    • SEO & Marketing
    • Social Media Tools
    SkytikSkytik
    Home»Guides»NPM packages are infected with malware, again
    Guides

    NPM packages are infected with malware, again

    AwaisBy AwaisNovember 26, 2025No Comments3 Mins Read0 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    NPM packages are infected with malware, again
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Summary

    • Shai Hulud v2 infected 500+ npm packages (700+ versions) and spilled into Java/Maven — yikes.
    • Compromised packages run a preinstall loader that downloads Bun and executes a 10MB obfuscated payload silently.
    • Payload exfiltrates env vars (GITHUB_TOKEN, NPM_TOKEN, AWS keys), scans for secrets; C2 self-heals via GitHub.

    These days, supply chain attacks targeting npm are not rare. It’s been a couple of months, but we’re back with yet another attack—this one affecting over 500 packages. Yikes.

    A sophisticated supply chain attack campaign dubbed “Shai Hulud v2” has compromised hundreds of packages within the npm ecosystem and has now spilled over into Java/Maven artifacts. The attack has already affected over 500 packages and 700 versions, infiltrating software from major vendors including Zapier, Postman, PostHog, AsyncAPI, and ENS Domains.

    From what we can gather, the infection vector relies on a two-stage loader designed to evade detection. Compromised packages contain a preinstall script in their package.json file that executes a file named setup_bun.js. This script acts as a stealthy loader that automatically detects the host operating system and architecture. It then locates or downloads the Bun runtime—a fast JavaScript runtime—and executes a heavy, 10MB obfuscated payload titled bun_environment.js. This process suppresses all standard output and error logs, so the malicious background processes remain undetected while the package is installing.

    It should be noted that the issue actually seems to spill over into the Maven ecosystem. Researchers observed that the malicious payload was present in org.mvnpm:posthog-node, a Maven artifact automatically generated from npm packages. This confirms that the automated bridging of software ecosystems can inadvertently bridge security vulnerabilities, effectively allowing JavaScript-based malware to contaminate Java environments. Yikes.

    The malware employs a resilient “self-healing” C2 infrastructure. Upon execution, it searches public GitHub repositories for a specific beacon phrase: “Sha1-Hulud: The Second Coming.” If found, the malware retrieves a hidden, triple-base64 encoded GitHub access token from the repository. This token is then used as the primary credential for data exfiltration. This lets the attackers just “re-seed” the campaign by creating new repositories if the previous ones are taken down, so it’s actually quite resistant to takedown efforts.

    The malware’s primary goal appears to be massive credential theft. It captures all environment variables, including GITHUB_TOKEN, NPM_TOKEN, and AWS_ACCESS_KEY_ID. Furthermore, it downloads and executes the TruffleHog security tool to aggressively scan the entire filesystem for hardcoded secrets.

    If you want to read more about the ins and outs of this issue, this report goes pretty in depth.

    Source: Socket

    infected malware NPM packages
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Awais
    • Website

    Related Posts

    How to daisy-chain multiple monitors from a single cable

    February 19, 2026

    I finally found a great use for my TV’s USB port

    February 19, 2026

    A 32-inch 4K OLED 240Hz monitor for $799.98 is the kind of “finish the setup” deal that’s hard to ignore

    February 18, 2026

    AI is helping hackers make new malware faster and more complex than ever – and things may only get tougher

    February 18, 2026

    Is your Galaxy Z Trifold at risk of breaking? Fresh reports detail worsening screen issues

    February 18, 2026

    Apple Cider Vinegar’s Real Benefits, According to Registered Dietitians

    February 18, 2026
    Leave A Reply Cancel Reply

    Top Posts

    At Least 32 People Dead After a Mine Bridge Collapsed Due to Overcrowding

    November 17, 20250 Views

    Here’s how I turned a Raspberry Pi into an in-car media server

    November 17, 20250 Views

    Beloved SF cat’s death fuels Waymo criticism

    November 17, 20250 Views
    Don't Miss

    How Google Profits From Demand You Already Own

    March 17, 2026

    Boost your skills with Growth Memo’s weekly expert insights. Subscribe for free! Branded search inflates…

    Extra-Creamy Deviled Eggs Recipe | Epicurious

    March 17, 2026

    How to Sell AI Services Without Selling Your Soul : Social Media Examiner

    March 17, 2026

    Ratio-Aware Layer Editing for Targeted Unlearning in Vision Transformers and Diffusion Models

    March 17, 2026
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    LinkedIn updates feed algorithm with LLM-powered ranking and retrieval

    March 17, 2026

    Trust Is The New Ranking Factor

    March 17, 2026
    Most Popular

    13 Trending Songs on TikTok in Nov 2025 (+ How to Use Them)

    November 18, 20257 Views

    How to watch the 2026 GRAMMY Awards online from anywhere

    February 1, 20263 Views

    Corporate Reputation Management Strategies | Sprout Social

    November 19, 20252 Views
    Our Picks

    At Least 32 People Dead After a Mine Bridge Collapsed Due to Overcrowding

    November 17, 2025

    Here’s how I turned a Raspberry Pi into an in-car media server

    November 17, 2025

    Beloved SF cat’s death fuels Waymo criticism

    November 17, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions
    • Disclaimer

    © 2025 skytik.cc. All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.