Skip to main content
institutional access

You are connecting from
Lake Geneva Public Library,
please login or register to take advantage of your institution's Ground News Plan.

Published loading...Updated

Protect Your Enterprise Now From the Shai-Hulud Worm and Npm Vulnerability in 6 Actionable Steps

Researchers say 400-plus package artifacts were compromised across npm, PyPI and Composer as attackers used valid provenance to hide credential-stealing malware.

  • On yesterday, attackers published 84 malicious versions across 42 TanStack packages on the Node Package Manager, each carrying valid provenance and signatures.
  • This incident is part of the ongoing Shai-Hulud campaign, which has compromised hundreds of packages across Node Package Manager, PyPI, and Composer since last September.
  • By hijacking valid OpenID Connect tokens, threat actors generated malicious packages with verifiable SLSA Build Level 3 attestations; Snyk researchers say the "attack produces valid SLSA Build Level 3 attestations for malicious packages."
  • The payload reads GitHub Actions process memory to collect credentials from more than 100 file paths, including AWS Secrets Manager, Kubernetes service account tokens, and SSH keys.
  • Researchers recommend that security teams rotate all credentials including GitHub tokens and Node Package Manager tokens, while auditing IDE directories for malicious files surviving installation.
Insights by Ground AI

11 Articles

An attacker released 84 malicious versions across 42 packages of the TanStack suite, stealing credentials from cloud environments. The article "JavaScript Attack Can Empty Cryptocurrency Wallets" was first published on CryptoNews - Bitcoin, Ethereum, and Cryptocurrency News.

Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

unsafe.sh broke the news on Tuesday, May 12, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal