A self-replicating worm has infected 187 packages in NPM

The attack on package maintainers in the NPM repository has reached a new level. In addition to using malware to intercept payments and confidential information, attackers have moved to injecting a worm into compromised packages to automate the insertion of malicious software into dependencies. The use of the worm was recorded after the compromise of the NPM package @ctrl/tinycolor, which has 2.2 million weekly downloads and is directly used in 964 packages. As a result of the worm's activity, the attack affected 187 packages, for which malicious releases were created (477 malicious releases).

In a new attack, after obtaining account parameters of a maintainer through phishing, attackers publish a release of a package with a worm that activates when the compromised package is installed among dependencies. Once activated, the worm searches for credentials in the current environment, downloading and running the TruffleHog utility. If it detects a connection token to the NPM registry, the worm automatically publishes a new malicious release, propagating through the dependency tree. In addition to the NPM access token, the worm captures access keys to GitHub and cloud services like AWS, Azure, and GCP (Google Cloud Platform), as well as other confidential data that the TruffleHog scanner can discover.

Malicious releases are created for the 20 most popular packages that the discovered NPM token can access. The functionality for publishing a release is implemented in the form of the NpmModule.updatePackage function, which uploads the source archive of the package, modifies the version number, and adds a postinstall hook to the package.json file, inserts the bundle.js handler, repackages the package, and publishes it. It supports operation in Linux and macOS.

The worm has been assigned the codename Shai-Hulud (a giant worm mentioned in the novel Dune). The discovered credentials are stored in GitHub through the creation of repositories named Shai-Hulud (for example, 'B611/Shai-Hulud'), and are also reflected in encoded form in the logs of GitHub Actions. A data.json file is placed in the created repository, which contains a string with base64 encoded information about the system, environment variables, and intercepted access keys. In CI based on GitHub, the worm creates a GitHub Actions handler (.github/workflows/shai-hulud-workflow.yml) to transfer information to an external host. Apparently, the attack is not limited to the mentioned 187 packages, as new repositories named Shai-Hulud and containing a data.json file continue to appear on GitHub.

A self-replicating worm has infected 187 packages in NPM

Among other things, as a result of the worm's activity, 25 packages from CrowdStrike, which develops tools for... protection against attacks supply chain dependencies. According to CrowdStrike, the compromised packages were not used in the Falcon platform, and the attack did not spread to customers. It has also been revealed that the previous wave of malicious releases on NPM, which occurred without the worm, affected the gemini-cli project developed by Google.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster