{"id":149530,"date":"2025-11-25T17:11:58","date_gmt":"2025-11-25T15:11:59","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/pri-pomoshhi-chervya-shai-hulud-skomprometirovano-600-npm-paketov"},"modified":"2025-11-25T17:11:58","modified_gmt":"2025-11-25T15:11:59","slug":"pri-pomoshhi-chervya-shai-hulud-skomprometirovano-600-npm-paketov","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/pri-pomoshhi-chervya-shai-hulud-skomprometirovano-600-npm-paketov","title":{"rendered":"Con l'aiuto del verme Shai-Hulud sono stati compromessi 600 pacchetti NPM","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u00c8 stata registrata un'altra attacco ai pacchetti nel repository NPM, condotto con l'uso di una modifica del verme auto-replicante Shai-Hulud, che inserisce malware nelle dipendenze. A causa dell'attacco, sono state pubblicate versioni malevole di 605 pacchetti, che complessivamente superano i 100 milioni di download.     <\/p>\n<p>Per eseguire l'attacco, i criminali informatici hanno intercettato tramite phishing i parametri dell'account del manutentore di uno dei pacchetti popolari, utilizzato come dipendenza da un gran numero di pacchetti. Approfittando dell'account compromesso, gli attaccanti hanno pubblicato una release del pacchetto, in cui \u00e8 stato aggiunto un codice per attivare il verme durante l'installazione del pacchetto compromesso tra le dipendenze. Il verme attivato cerca le credenziali nell'ambiente attuale, scaricando e avviando l'utility TruffleHog.     <\/p>\n<p>Nel caso venga scoperto un token di connessione al catalogo NPM, il verme pubblica automaticamente nuove release malevole per pacchetti sviluppati nell'ambiente attuale. In questo modo, l'intero albero delle dipendenze viene compromesso a cascata. Oltre al token NPM, il verme salva le chiavi di accesso a GitHub e ai servizi cloud AWS, Azure e GCP (Google Cloud Platform), oltre a variabili di ambiente e altri dati sensibili che \u00e8 in grado di identificare il scanner TruffleHog.     <\/p>\n<p>I dati riservati trovati nel sistema vengono pubblicati su GitHub attraverso la creazione di repository con nomi casuali (ad esempio, &#171;qzx15djl71alh6p80h&#187;) e la frase &#171;Sha1-Hulud: The Second Coming&#187; nella descrizione, oltre ad essere mostrati in forma codificata nei log di GitHub Actions. Nel repository creato viene posizionato un file in formato JSON (come jsonactionsSecrets.json o contents.json), contenente una stringa con informazioni sul sistema codificate in base64, variabili d'ambiente e dati catturati. Per inviare informazioni al di fuori dei sistemi di integrazione continua basati su GitHub, il worm crea un gestore di GitHub Actions chiamato &#171;.github\/workflows\/formatter_123456789.yml&#187; e configura un runner chiamato SHA1HULUD.    <\/p>\n<p>Le differenze rispetto a un attacco simile di settembre riguardano un metodo diverso di inserimento del codice dannoso nel pacchetto. Nei rilasci malevoli generati dal worm si dichiara l\u2019implementazione del supporto per la piattaforma JavaScript Bun. Nel file package.json, nella sezione &#171;preinstall&#187;, che definisce gli script eseguiti prima dell'inizio dell'installazione, viene aggiunto il comando &#171;node setup_bun.js&#187;.   <center><img decoding=\"async\" alt=\"Con l&#039;aiuto del verme Shai-Hulud sono stati compromessi 600 pacchetti NPM\" src=\"\/wp-content\/uploads\/2025\/11\/9b6fe1ba9d28fa5432b53d051ad21724.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>  <\/p>\n<p>Nel file &#171;setup_bun.js&#187; \u00e8 presente del codice per eseguire uno script offuscato &#171;bun_environment.js&#187;, contenente il codice del worm. Per la sua ulteriore diffusione, il worm trova il codice dei pacchetti, modifica il file package.json (incrementa il numero di versione e include la chiamata a setup_bun.js), aggiunge i file setup_bun.js e bun_environment.js, riporta il pacchetto e esegue il comando &#171;npm publish&#187; per pubblicare un nuovo rilascio.    <\/p>\n<p>Tra i pacchetti popolari compromessi figurano: @zapier\/zapier-sdk (2,8 milioni di download a settimana), @posthog\/core (2,8 milioni), posthog-node (1,5 milioni), @asyncapi\/specs (1,4 milioni), @postman\/tunnel-agent (1,2 milioni). Si ritiene che l'attacco sia iniziato con la compromissione del pacchetto @asyncapi\/specs.<br \/>\n<br \/>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=64322\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u0432\u0442\u043e\u0440\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM, \u043f\u0440\u043e\u0432\u043e\u0434\u0438\u043c\u0430\u044f \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u043c\u043e\u0434\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0441\u0430\u043c\u043e\u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0435\u0433\u043e\u0441\u044f \u0447\u0435\u0440\u0432\u044f Shai-Hulud, \u043f\u043e\u0434\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u0433\u043e \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e \u0432 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438. \u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u0430\u0442\u0430\u043a\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 605 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u0432 \u0441\u0443\u043c\u043c\u0435 \u0431\u043e\u043b\u0435\u0435 100 \u043c\u043b\u043d \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a. \u0414\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u0430\u0442\u0430\u043a\u0438 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u043f\u0443\u0442\u0451\u043c \u0444\u0438\u0448\u0438\u043d\u0433\u0430 \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u0438\u043b\u0438 \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u044b \u0443\u0447\u0451\u0442\u043d\u043e\u0439 \u0437\u0430\u043f\u0438\u0441\u0438 \u0441\u043e\u043f\u0440\u043e\u0432\u043e\u0436\u0434\u0430\u044e\u0449\u0435\u0433\u043e \u043e\u0434\u043d\u043e\u0433\u043e \u0438\u0437 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0433\u043e \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438 \u0443 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":149531,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-149530","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u0432\u0442\u043e\u0440\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM, \u043f\u0440\u043e\u0432\u043e\u0434\u0438\u043c\u0430\u044f \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u043c\u043e\u0434\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0441\u0430\u043c\u043e\u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0435\u0433\u043e\u0441\u044f \u0447\u0435\u0440\u0432\u044f Shai-Hulud, \u043f\u043e\u0434\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u0433\u043e \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e \u0432 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/pri-pomoshhi-chervya-shai-hulud-skomprometirovano-600-npm-paketov\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041f\u0440\u0438 \u043f\u043e\u043c\u043e\u0449\u0438 \u0447\u0435\u0440\u0432\u044f Shai-Hulud \u0441\u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u043e 600 NPM-\u043f\u0430\u043a\u0435\u0442\u043e\u0432 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u0432\u0442\u043e\u0440\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM, \u043f\u0440\u043e\u0432\u043e\u0434\u0438\u043c\u0430\u044f \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u043c\u043e\u0434\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0441\u0430\u043c\u043e\u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0435\u0433\u043e\u0441\u044f \u0447\u0435\u0440\u0432\u044f Shai-Hulud, \u043f\u043e\u0434\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u0433\u043e \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e \u0432 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/pri-pomoshhi-chervya-shai-hulud-skomprometirovano-600-npm-paketov\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-11-25T15:11:59+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-11-25T15:11:59+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Con il worm Shai-Hulud sono stati compromessi 600 pacchetti NPM | ProHoster","description":"\u00c8 stata registrata una seconda attacco ai pacchetti nel repository NPM, condotta utilizzando una modifica del worm autopropagante Shai-Hulud, che inserisce software dannoso nelle dipendenze.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/pri-pomoshhi-chervya-shai-hulud-skomprometirovano-600-npm-paketov","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041f\u0440\u0438 \u043f\u043e\u043c\u043e\u0449\u0438 \u0447\u0435\u0440\u0432\u044f Shai-Hulud \u0441\u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u043e 600 NPM-\u043f\u0430\u043a\u0435\u0442\u043e\u0432 | ProHoster","og:description":"\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u0432\u0442\u043e\u0440\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM, \u043f\u0440\u043e\u0432\u043e\u0434\u0438\u043c\u0430\u044f \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u043c\u043e\u0434\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0441\u0430\u043c\u043e\u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0435\u0433\u043e\u0441\u044f \u0447\u0435\u0440\u0432\u044f Shai-Hulud, \u043f\u043e\u0434\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u0433\u043e \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e \u0432 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/pri-pomoshhi-chervya-shai-hulud-skomprometirovano-600-npm-paketov","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2025-11-25T15:11:59+00:00","article:modified_time":"2025-11-25T15:11:59+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"149530","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 16:12:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 16:12:19","updated":"2026-01-23 16:12:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/149530","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=149530"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/149530\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media\/149531"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=149530"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=149530"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=149530"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}