Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

Shai-Hulud 2 Malware Campaign Targets GitHub and Cloud Credentials Using Bun Runtime

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Henrik Plate
Word Count
2,479
Company Posts That Month
14
Language
English
Hacker News Points
-
Post removed?
No
Summary

The Shai-Hulud software supply chain attack has intensified, impacting the npm ecosystem by exploiting new execution techniques that lead to credential theft, supply-chain propagation, and potential data loss. Targeting npm packages from organizations like Zapier, ENS Domains, Postman, and PostHog, the attack employs the "Bun" runtime for stealthier execution compared to the more monitored Node.js. The attack is triggered by a malicious pre-install script in "package.json" files, spreading through developer environments and CI/CD systems, particularly affecting GitHub Actions by stealing repository secrets. Although 99% of affected package versions were removed from npm, over 26,000 repositories have been compromised, leveraging GitHub tokens to automatically infect additional repositories. The malware's capabilities include credential harvesting, self-replication, and remote code execution, with destructive behaviors such as data erasure on both Windows and Linux systems. The attack underscores the need for vigilant monitoring, prompt credential rotation, and enhanced security practices to mitigate supply chain risks.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.