{"id":143668,"date":"2025-09-17T11:11:56","date_gmt":"2025-09-17T09:11:57","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/samorasprostranyayushhijsya-cherv-porazil-187-paketov-v-npm"},"modified":"2026-02-08T21:43:52","modified_gmt":"2026-02-08T19:43:52","slug":"samorasprostranyayushhijsya-cherv-porazil-187-paketov-v-npm","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/samorasprostranyayushhijsya-cherv-porazil-187-paketov-v-npm","title":{"rendered":"Un worm auto-replicante ha colpito 187 pacchetti in NPM","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>L'attacco ai pacchetti di accompagnamento nel repository NPM ha raggiunto un nuovo livello. Oltre all'uso di malware per intercettare pagamenti e informazioni riservate, gli attaccanti hanno iniziato a implementare un worm nei pacchetti compromessi per automatizzare l'inserimento di malware nelle dipendenze. L'uso del worm \u00e8 stato registrato dopo la compromissione del pacchetto NPM @ctrl\/tinycolor, che ha 2,2 milioni di download settimanali ed \u00e8 stato utilizzato come dipendenza diretta in 964 pacchetti. A seguito dell'attivit\u00e0 del worm, l'attacco ha colpito 187 pacchetti, per i quali sono state create versioni malevole (477 versioni malevole).       <\/p>\n<p>Durante un nuovo attacco, dopo aver ottenuto le credenziali dell'account di accompagnamento tramite phishing, gli attaccanti pubblicano una versione del pacchetto con un worm che si attiva quando viene installato un pacchetto compromesso tra le dipendenze. Dopo l'attivazione, il worm cerca le credenziali nell'ambiente attuale, scaricando e avviando l'utilit\u00e0 TruffleHog. Se viene trovato un token di connessione al catalogo NPM, il worm pubblica automaticamente una nuova versione malevola e colpisce a catena l'albero delle dipendenze. Oltre al token di accesso a NPM, il worm conserva le chiavi di accesso a GitHub e ai servizi cloud AWS, Azure e GCP (Google Cloud Platform), cos\u00ec come altri dati riservati che il scanner TruffleHog \u00e8 in grado di rilevare.      <\/p>\n<p>Le versioni malevole vengono create per i 20 pacchetti pi\u00f9 popolari a cui il token NPM trovato ha accesso. La funzionalit\u00e0 di pubblicazione della versione \u00e8 implementata sotto forma della funzione NpmModule.updatePackage, che carica l'archivio sorgente del pacchetto, modifica il numero di versione e aggiunge un hook postinstall al file package.json, inserisce il gestore bundle.js, ricompone il pacchetto e lo pubblica. \u00c8 supportato il funzionamento su Linux e macOS.        <\/p>\n<p>Il verme \u00e8 stato assegnato il nome in codice Shai-Hulud (un verme gigante menzionato nel romanzo Dune). Le credenziali trovate nel sistema vengono pubblicate su GitHub tramite la creazione di repository chiamati Shai-Hulud (ad esempio, \u00abB611\/Shai-Hulud\u00bb), e sono anche codificate nei log di GitHub Actions. In ogni repository creato \u00e8 presente un file data.json che contiene una stringa con informazioni sul sistema, variabili d'ambiente e chiavi d'accesso intercettate, codificate con il metodo base64. Nel CI basato su GitHub, per trasferire informazioni a un host esterno, il verme crea un gestore di GitHub Actions (.github\/workflows\/shai-hulud-workflow.yml). A quanto pare, l'attacco non \u00e8 limitato ai 187 pacchetti menzionati, poich\u00e9 continuano a comparire nuovi repository su GitHub con il nome Shai-Hulud e un file data.json.                    <center><img decoding=\"async\" alt=\"Un worm auto-replicante ha colpito 187 pacchetti in NPM\" src=\"\/wp-content\/uploads\/2025\/09\/9192d80585dbe659249741c4365d04aa.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>          <\/p>\n<p>Tra l'altro, a seguito dell'attivit\u00e0 del verme, sono stati colpiti 25 pacchetti della societ\u00e0 CrowdStrike, che sviluppa strumenti per <a href=\"https:\/\/prohoster.info\/it\/zhashchita-ot-ddos\/\"  data-wpil-monitor-id=\"424\">la protezione dagli attacchi<\/a> tramite dipendenze (Supply Chain). Secondo quanto dichiarato da CrowdStrike, i pacchetti compromessi non erano utilizzati nella piattaforma Falcon e l'attacco non si \u00e8 diffuso ai clienti. \u00c8 stato anche reso noto che la scorsa ondata di pubblicazione di versioni dannose in NPM, effettuata senza il verme, ha colpito il progetto gemini-cli, sviluppato da Google.<br \/>\n<br \/>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=63894\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0410\u0442\u0430\u043a\u0430 \u043d\u0430 \u0441\u043e\u043f\u0440\u043e\u0432\u043e\u0436\u0434\u0430\u044e\u0449\u0438\u0445 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM \u043f\u0435\u0440\u0435\u0448\u043b\u0430 \u043d\u0430 \u043d\u043e\u0432\u044b\u0439 \u0443\u0440\u043e\u0432\u0435\u043d\u044c. \u0412 \u0434\u043e\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u043a \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044e \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e \u0434\u043b\u044f \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u0430 \u043f\u043b\u0430\u0442\u0435\u0436\u0435\u0439 \u0438 \u043a\u043e\u043d\u0444\u0438\u0434\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0439 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0435 \u043f\u0435\u0440\u0435\u0448\u043b\u0438 \u043a \u0432\u043d\u0435\u0434\u0440\u0435\u043d\u0438\u044e \u0432 \u0441\u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u0447\u0435\u0440\u0432\u044f \u0434\u043b\u044f \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e \u0432 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438. \u041f\u0440\u0438\u043c\u0435\u043d\u0435\u043d\u0438\u0435 \u0447\u0435\u0440\u0432\u044f \u0437\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u043e \u043f\u043e\u0441\u043b\u0435 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 NPM-\u043f\u0430\u043a\u0435\u0442\u0430 @ctrl\/tinycolor, \u0438\u043c\u0435\u044e\u0449\u0435\u0433\u043e 2.2 \u043c\u043b\u043d \u0435\u0436\u0435\u043d\u0435\u0434\u0435\u043b\u044c\u043d\u044b\u0445 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a \u0438 \u0437\u0430\u0434\u0435\u0439\u0441\u0442\u0432\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u043f\u0440\u044f\u043c\u043e\u0439 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":143669,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-143668","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0410\u0442\u0430\u043a\u0430 \u043d\u0430 \u0441\u043e\u043f\u0440\u043e\u0432\u043e\u0436\u0434\u0430\u044e\u0449\u0438\u0445 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM \u043f\u0435\u0440\u0435\u0448\u043b\u0430 \u043d\u0430 \u043d\u043e\u0432\u044b\u0439 \u0443\u0440\u043e\u0432\u0435\u043d\u044c.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/samorasprostranyayushhijsya-cherv-porazil-187-paketov-v-npm\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0421\u0430\u043c\u043e\u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0438\u0439\u0441\u044f \u0447\u0435\u0440\u0432\u044c \u043f\u043e\u0440\u0430\u0437\u0438\u043b 187 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0432 NPM | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0410\u0442\u0430\u043a\u0430 \u043d\u0430 \u0441\u043e\u043f\u0440\u043e\u0432\u043e\u0436\u0434\u0430\u044e\u0449\u0438\u0445 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM \u043f\u0435\u0440\u0435\u0448\u043b\u0430 \u043d\u0430 \u043d\u043e\u0432\u044b\u0439 \u0443\u0440\u043e\u0432\u0435\u043d\u044c.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/samorasprostranyayushhijsya-cherv-porazil-187-paketov-v-npm\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-09-17T09:11:57+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-02-08T19:43:52+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Un verme autoreplicante ha colpito 187 pacchetti in NPM | ProHoster","description":"L'attacco ai pacchetti di accompagnamento nel repository NPM ha raggiunto un nuovo livello.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/samorasprostranyayushhijsya-cherv-porazil-187-paketov-v-npm","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0421\u0430\u043c\u043e\u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0438\u0439\u0441\u044f \u0447\u0435\u0440\u0432\u044c \u043f\u043e\u0440\u0430\u0437\u0438\u043b 187 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0432 NPM | ProHoster","og:description":"\u0410\u0442\u0430\u043a\u0430 \u043d\u0430 \u0441\u043e\u043f\u0440\u043e\u0432\u043e\u0436\u0434\u0430\u044e\u0449\u0438\u0445 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM \u043f\u0435\u0440\u0435\u0448\u043b\u0430 \u043d\u0430 \u043d\u043e\u0432\u044b\u0439 \u0443\u0440\u043e\u0432\u0435\u043d\u044c.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/samorasprostranyayushhijsya-cherv-porazil-187-paketov-v-npm","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2025-09-17T09:11:57+00:00","article:modified_time":"2026-02-08T19:43:52+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"143668","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-08 19:43:52","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 14:50:19","updated":"2026-02-08 19:43:52","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/143668","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=143668"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/143668\/revisions"}],"predecessor-version":[{"id":157614,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/143668\/revisions\/157614"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media\/143669"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=143668"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=143668"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=143668"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}