All Topics
All Topics
Technology
Technology
AI
AI
Business
Business
Entertainment
Entertainment
News
News
Programming
Programming
Security
Security
Science
Science
Design
Design
Environment
Environment
Finance
Finance
Crypto
Crypto
Politics
Politics
Sports
Sports
Education
Education
Gaming
Gaming
Art
Art
Music
Music
Health
Health
Books
Books
Food
Food
Travel
Travel
Personal
Personal
Bluesky
Twitter

Supply Chain Attack Wave Targets npm Packages and Go Ecosystem via Mini Shai-Hulud Malware Family

By

SocketDev

9d ago· 7 min readenNews

Summary

Socket Threat Research is tracking a new supply chain attack wave linked to the Mini Shai-Hulud, Miasma, and Hades malware family. The campaign targets LeoPlatform/RStreams npm packages, three llxlr-published npm packages, and the Verana Blockchain Go module. The attack abuses multiple techniques including npm poisoning, GitHub Actions, binding.gyp execution, Bun-staged payloads, and developer-tool hooks to steal secrets and spread across ecosystems.

Source

bskySupply Chain Attack Wave Targets npm Packages and Go Ecosystem via Mini Shai-Hulud Malware Familyhendryadrian.com

Key quotes

· 2 pulled
Socket Threat Research is tracking a new supply chain attack wave tied to the Mini Shai-Hulud, Miasma, and Hades malware family
The campaign abuses npm poisoning, GitHub Actions, binding.gyp execution, Bun-staged payloads, and developer-tool hooks to steal secrets and spread across ecosystems
Snippet from the RSS feed
Socket Threat Research is tracking a new supply chain attack wave tied to the Mini Shai-Hulud, Miasma, and Hades malware family, affecting LeoPlatform/RStreams npm packages, three llxlr-published npm packages, and the Verana Blockchain Go m...

You might also wanna read

Comments

Sign in to join the conversation.

No comments yet. Be the first.