Shai-Hulud 2 Malware Campaign Targets GitHub and Cloud Credentials Using Bun Runtime
Blog post from Endor Labs
The Shai-Hulud software supply chain attack has intensified, impacting the npm ecosystem by exploiting new execution techniques that lead to credential theft, supply-chain propagation, and potential data loss. Targeting npm packages from organizations like Zapier, ENS Domains, Postman, and PostHog, the attack employs the "Bun" runtime for stealthier execution compared to the more monitored Node.js. The attack is triggered by a malicious pre-install script in "package.json" files, spreading through developer environments and CI/CD systems, particularly affecting GitHub Actions by stealing repository secrets. Although 99% of affected package versions were removed from npm, over 26,000 repositories have been compromised, leveraging GitHub tokens to automatically infect additional repositories. The malware's capabilities include credential harvesting, self-replication, and remote code execution, with destructive behaviors such as data erasure on both Windows and Linux systems. The attack underscores the need for vigilant monitoring, prompt credential rotation, and enhanced security practices to mitigate supply chain risks.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.