Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting 400+ packages across multiple publishers, delivering a self-propagating credential-stealing worm called Mini Shai-Hulud. The malware executes via npm preinstall lifecycle hooks, harvests credentials from developer workstations and CI/CD environments, authenticates to cloud and infrastructure services to enumerate additional secrets, and uses stolen npm publishing tokens to automatically modify and republish packages — creating worm-like propagation. Persistence is achieved by injecting malicious configuration files into Claude and VS Code workspace settings within compromised GitHub repositories.
Bun JavaScript
1 post
ChainDrop supply chain compromise: Anatomy of a self-propagating worm