Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Malicious Software Abuses npm Preinstall to Steal Sensitive Data, Compromising 25,000 GitHub Repositories

Malicious Software Abuses npm Preinstall to Steal Sensitive Data, Compromising 25,000 GitHub Repositories

Bitget-RWA2025/11/24 13:10
By:Bitget-RWA

- Wiz Research identified Shai-Hulud 2.0, a supply-chain attack exploiting npm's `preinstall` phase to hijack 25,000+ GitHub repos and steal secrets from crypto/developer tools. - Malware infiltrates packages like `@zapier/zapier-sdk` and `@ensdomains/ens-validation`, using GitHub runners for credential theft and workflow injection across ecosystems. - Attackers create self-hosted runners, exfiltrate secrets as artifacts, and delete traces, with new compromises emerging at 1,000 per 30 minutes. - Security

An npm supply-chain attack known as Shai-Hulud 2.0 has infiltrated widely used libraries in the developer and cryptocurrency sectors, including

(ENS) utilities and Zapier connections. Discovered by Wiz Research, this operation exploits the `preinstall` script during package setup, allowing attackers to steal sensitive data and insert malicious workflows into GitHub repositories . The attack has already impacted more than 25,000 repositories, with new incidents surfacing at a pace of 1,000 every half hour, highlighting the speed at which it is spreading.

This threat uses altered versions of authentic npm packages that, once installed, carry out credential theft and data extraction. Unlike earlier Shai-Hulud campaigns, this version introduces additional payloads like `setup_bun.js` and `bun_environment.js`, broadening its impact to platforms such as PostHog, Postman, and AsyncAPI. The malware enlists compromised systems as self-hosted GitHub runners and establishes workflows that let attackers run arbitrary commands through GitHub discussions. It also steals secrets from GitHub repositories by

as artifacts, then erases evidence of its actions.

Several prominent packages have been verified as compromised, including `@zapier/zapier-sdk` (versions 0.15.5–0.15.7), `@ensdomains/ens-validation` (0.1.1), and `@posthog/agent` (1.24.1). The campaign has also affected packages from smaller publishers like `@trigo/`, `@orbitgtbelgium/`, and `@louisle2/`. Wiz Research observed that while the techniques are similar to previous Shai-Hulud incidents, differences in payload design and spread suggest the possibility of new threat actors.

, but the persistent nature of the attack points to a highly organized operation.

Security professionals are strongly encouraged to act without delay. Suggested steps include uninstalling and replacing affected packages, purging npm caches, and rotating credentials like GitHub personal access tokens (PATs) and cloud provider keys. Developers should also review GitHub environments for repositories named "Shai-Hulud" or workflows with unusual commit histories.

by restricting the use of lifecycle scripts and limiting outbound connections to trusted domains is essential to reduce risk.

The breadth of this attack exposes significant weaknesses in software supply chains. Wiz Research pointed out that the attackers exploit npm’s extensive reach, with malicious packages being downloaded in various environments before removal. While GitHub is actively removing repositories tied to the campaign, new ones continue to appear, making containment more difficult.

As the situation develops, cybersecurity experts are watching to see if this marks a turning point in supply-chain attacks on open-source software. Developers are urged to keep dependencies up to date and use automated solutions to identify malicious behavior as it happens.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Solana News Update: Sunrise Seeks to Resolve Solana's Liquidity Splintering through Immediate Listings

- Wormhole Labs launches Sunrise, a Solana-native listing platform enabling instant liquidity for new tokens like MON, addressing DeFi fragmentation. - The platform uses NTT framework to natively onboard cross-chain assets, retaining liquidity within Solana and integrating with DEXs like Orb and Jupiter. - MON's day-one trading demonstrates Sunrise's potential to solidify Solana as a hub for tokenized assets, with TVL rising 32.7% to $11.5B in Q3 2025. - Analysts highlight Sunrise's role in standardizing h

Bitget-RWA2025/11/24 13:46
Solana News Update: Sunrise Seeks to Resolve Solana's Liquidity Splintering through Immediate Listings

India’s Cryptocurrency Conundrum: Can Updated VDA Regulations Safeguard Progress or Hinder Expansion?

- India's VDA regulatory review aims to align crypto rules with global standards, addressing consumer protection gaps and market integrity risks. - Current fragmented regulations, including 30% profit tax and weak custody laws, have driven users to offshore platforms, stifling local innovation. - Proposed reforms include risk-based token classification, licensing for exchanges, and RWA frameworks to balance innovation with systemic risk mitigation. - A balanced approach could attract investment and strengt

Bitget-RWA2025/11/24 13:46
India’s Cryptocurrency Conundrum: Can Updated VDA Regulations Safeguard Progress or Hinder Expansion?

Bitcoin Updates Today: Bearish Pressure Mounts, Yet Optimistic Bulls Anticipate Future Expansion

- Bitcoin's bearish technical indicators reinforce downward pressure despite short-term recovery attempts. - Ethereum and altcoins mirror Bitcoin's weakness, with $2B in crypto liquidations intensifying selling pressure. - Long-term fundamentals project $17.14B crypto market growth by 2033 driven by institutional adoption and regulatory clarity. - Thailand's Bitkub plans $200M Hong Kong IPO amid local market struggles, highlighting regional listing strategy shifts. - Persistent bearish momentum remains, wi

Bitget-RWA2025/11/24 13:46
Bitcoin Updates Today: Bearish Pressure Mounts, Yet Optimistic Bulls Anticipate Future Expansion

Biomarkers Shine, Results Disappoint: Novo's Attempt at Alzheimer's Falls Short

- Novo Nordisk's Alzheimer's trials for semaglutide failed to meet primary endpoints, causing a 9% premarket stock drop to a multi-year low. - The $3.8B trial showed no disease progression slowing despite biomarker improvements, with UBS estimating only 10% success probability beforehand. - Market ripple effects included Eli Lilly's 0.5% decline and Biogen's 2.7% rise, highlighting GLP-1 drug competition in neurodegenerative therapies. - This setback compounds Novo's challenges: 50% YTD stock decline, obes

Bitget-RWA2025/11/24 13:46
Biomarkers Shine, Results Disappoint: Novo's Attempt at Alzheimer's Falls Short