Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Malicious Software Abuses npm Preinstall to Steal Sensitive Data, Compromising 25,000 GitHub Repositories

Malicious Software Abuses npm Preinstall to Steal Sensitive Data, Compromising 25,000 GitHub Repositories

Bitget-RWA2025/11/24 13:10
By:Bitget-RWA

- Wiz Research identified Shai-Hulud 2.0, a supply-chain attack exploiting npm's `preinstall` phase to hijack 25,000+ GitHub repos and steal secrets from crypto/developer tools. - Malware infiltrates packages like `@zapier/zapier-sdk` and `@ensdomains/ens-validation`, using GitHub runners for credential theft and workflow injection across ecosystems. - Attackers create self-hosted runners, exfiltrate secrets as artifacts, and delete traces, with new compromises emerging at 1,000 per 30 minutes. - Security

An npm supply-chain attack known as Shai-Hulud 2.0 has infiltrated widely used libraries in the developer and cryptocurrency sectors, including

(ENS) utilities and Zapier connections. Discovered by Wiz Research, this operation exploits the `preinstall` script during package setup, allowing attackers to steal sensitive data and insert malicious workflows into GitHub repositories . The attack has already impacted more than 25,000 repositories, with new incidents surfacing at a pace of 1,000 every half hour, highlighting the speed at which it is spreading.

This threat uses altered versions of authentic npm packages that, once installed, carry out credential theft and data extraction. Unlike earlier Shai-Hulud campaigns, this version introduces additional payloads like `setup_bun.js` and `bun_environment.js`, broadening its impact to platforms such as PostHog, Postman, and AsyncAPI. The malware enlists compromised systems as self-hosted GitHub runners and establishes workflows that let attackers run arbitrary commands through GitHub discussions. It also steals secrets from GitHub repositories by

as artifacts, then erases evidence of its actions.

Several prominent packages have been verified as compromised, including `@zapier/zapier-sdk` (versions 0.15.5–0.15.7), `@ensdomains/ens-validation` (0.1.1), and `@posthog/agent` (1.24.1). The campaign has also affected packages from smaller publishers like `@trigo/`, `@orbitgtbelgium/`, and `@louisle2/`. Wiz Research observed that while the techniques are similar to previous Shai-Hulud incidents, differences in payload design and spread suggest the possibility of new threat actors.

, but the persistent nature of the attack points to a highly organized operation.

Security professionals are strongly encouraged to act without delay. Suggested steps include uninstalling and replacing affected packages, purging npm caches, and rotating credentials like GitHub personal access tokens (PATs) and cloud provider keys. Developers should also review GitHub environments for repositories named "Shai-Hulud" or workflows with unusual commit histories.

by restricting the use of lifecycle scripts and limiting outbound connections to trusted domains is essential to reduce risk.

The breadth of this attack exposes significant weaknesses in software supply chains. Wiz Research pointed out that the attackers exploit npm’s extensive reach, with malicious packages being downloaded in various environments before removal. While GitHub is actively removing repositories tied to the campaign, new ones continue to appear, making containment more difficult.

As the situation develops, cybersecurity experts are watching to see if this marks a turning point in supply-chain attacks on open-source software. Developers are urged to keep dependencies up to date and use automated solutions to identify malicious behavior as it happens.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Stablecoin Market Exceeds $280B as ECB Warns of Potential Systemic Risks

- Stablecoin market exceeds $280B, driven by regulatory clarity and institutional adoption, capturing 8% of crypto assets. - ECB warns of systemic risks from stablecoin concentration, de-pegging events, and mass redemption "runs" threatening global markets. - USDC overtakes USDT in onchain activity due to regulatory alignment, with Circle's market cap rising 72% YTD to $74B. - ECB calls for global regulatory coordination to address cross-border arbitrage gaps and prevent destabilizing retail deposit shifts

Bitget-RWA2025/11/25 06:12
Stablecoin Market Exceeds $280B as ECB Warns of Potential Systemic Risks

Bitcoin News Update: MicroStrategy Faces an Identity Dilemma—Is It a Technology Company or a Bitcoin Holding Entity?

- MicroStrategy faces potential MSCI index reclassification as a Bitcoin investment vehicle, risking $8.8B in passive fund outflows. - The debate centers on whether crypto-heavy firms should be classified as operating businesses or passive funds, impacting capital access and valuation. - CEO Michael Saylor defends MSTR as a "structured finance company," leveraging Bitcoin-backed securities to differentiate from passive vehicles. - Compressed stock-to-NAV multiples and Bitcoin's price slump threaten MSTR's

Bitget-RWA2025/11/25 06:12
Bitcoin News Update: MicroStrategy Faces an Identity Dilemma—Is It a Technology Company or a Bitcoin Holding Entity?

Japan Sets Out to Rebuild Investor Confidence in Crypto Following Significant Security Breaches

- Japan's FSA will mandate crypto exchanges to hold liability reserves proportional to trading volumes and security risks, modeled after traditional securities safeguards. - The reform responds to major breaches like the 2024 DMM Bitcoin hack ($312M stolen) and allows exchanges to offset reserve costs via insurance policies. - New rules require segregating user funds from corporate assets and reclassify crypto as securities under the Financial Instruments Act to enable investment products. - Experts view t

Bitget-RWA2025/11/25 06:12
Japan Sets Out to Rebuild Investor Confidence in Crypto Following Significant Security Breaches

Bitcoin News Today: Bitcoin's Rebound Fails to Ease Crypto's Liquidity Crunch

- Bitcoin's $80,000 rebound failed to reverse crypto's liquidity crisis as structural risks deepen amid macroeconomic pressures and thinning market liquidity. - Total crypto market cap fell below $3 trillion with $950M+ liquidations, while Bitcoin's dominance dropped below 49% as capital rotated into altcoins like HBAR and HYPE. - Institutional divergence emerged: spot ETFs saw $1.38B redemptions while on-chain accumulators added 42,000 BTC, contrasting with long-term investors offloading ~42,000 BTC this

Bitget-RWA2025/11/25 05:54
Bitcoin News Today: Bitcoin's Rebound Fails to Ease Crypto's Liquidity Crunch