{"id":143668,"date":"2025-09-17T11:11:56","date_gmt":"2025-09-17T09:11:57","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/samorasprostranyayushhijsya-cherv-porazil-187-paketov-v-npm"},"modified":"2026-02-08T21:43:52","modified_gmt":"2026-02-08T19:43:52","slug":"samorasprostranyayushhijsya-cherv-porazil-187-paketov-v-npm","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/samorasprostranyayushhijsya-cherv-porazil-187-paketov-v-npm","title":{"rendered":"Un vierme auto-replicant a infectat 187 de pachete \u00een NPM","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Atacul asupra pachetelor de mentenan\u021b\u0103 din depozitul NPM a trecut la un nou nivel. Pe l\u00e2ng\u0103 utilizarea de software mali\u021bios pentru interceptarea pl\u0103\u021bilor \u0219i a informa\u021biilor confiden\u021biale, atacatorii au \u00eenceput s\u0103 implementeze un vierme \u00een pachetele compromise pentru a automatiza inserarea de software mali\u021bios \u00een dependen\u021be. Utilizarea viermilor a fost raportat\u0103 dup\u0103 compromiterea pachetului NPM @ctrl\/tinycolor, care are 2,2 milioane de desc\u0103rc\u0103ri s\u0103pt\u0103m\u00e2nale \u0219i este folosit ca dependen\u021b\u0103 direct\u0103 \u00een 964 de pachete. Ca urmare a activit\u0103\u021bii viermilor, atacul a afectat 187 de pachete pentru care au fost generate versiuni mali\u021bioase (477 de versiuni mali\u021bioase).       <\/p>\n<p>\u00cen cadrul unui nou atac, dup\u0103 ce au ob\u021binut parametrii contului de mentenan\u021b\u0103 prin phishing, atacatorii public\u0103 o versiune a pachetului cu un vierme care se activeaz\u0103 la instalarea pachetului compromis ca parte a dependen\u021belor. Dup\u0103 activare, viermele caut\u0103 acreditive \u00een mediu, \u00eenc\u0103rc\u00e2nd \u0219i rul\u00e2nd utilitarul TruffleHog. Dac\u0103 se descoper\u0103 un token de conexiune la directorul NPM, viermele public\u0103 automat o nou\u0103 versiune mali\u021bioas\u0103 \u0219i afecteaz\u0103 \u00een lan\u021b arborele dependen\u021belor. Pe l\u00e2ng\u0103 tokenul de acces la NPM, viermele salveaz\u0103 cheile de acces la GitHub \u0219i la serviciile cloud AWS, Azure \u0219i GCP (Google Cloud Platform), precum \u0219i alte date confiden\u021biale pe care le poate detecta scanner-ul TruffleHog.      <\/p>\n<p>Versiunile mali\u021bioase sunt generate pentru cele 20 de pachete cele mai populare, la care are acces tokenul NPM g\u0103sit. Func\u021bionalitatea de publicare a versiunii este implementat\u0103 sub forma func\u021biei NpmModule.updatePackage, care \u00eencarc\u0103 arhiva surs\u0103 a pachetului, modific\u0103 num\u0103rul versiunii \u0219i adaug\u0103 un hook postinstall \u00een fi\u0219ierul package.json, \u00eenlocuie\u0219te handler-ul bundle.js, reambaleaz\u0103 pachetul \u0219i \u00eel public\u0103. Este suportat\u0103 func\u021bionarea at\u00e2t pe Linux, c\u00e2t \u0219i pe macOS.        <\/p>\n<p>Creeper-ului i-a fost atribuit numele de cod Shai-Hulud (un vierme uria\u0219 men\u021bionat \u00een romanul Dune). Credentialele g\u0103site \u00een sistem sunt publicate pe GitHub prin crearea de repozitorii cu numele Shai-Hulud (de exemplu, &#171;B611\/Shai-Hulud&#187;), iar acestea sunt de asemenea reflectate \u00een mod codificat \u00een jurnalele GitHub Actions. \u00cen repozitoriul creat se afl\u0103 un fi\u0219ier data.json, care con\u021bine un \u0219ir de informa\u021bii despre sistem, variabile de mediu \u0219i chei de acces interceptate, codificate prin metoda base64. \u00cen CI bazat pe GitHub, pentru a transfera informa\u021biile c\u0103tre un host extern, viermele creeaz\u0103 un handler GitHub Actions (.github\/workflows\/shai-hulud-workflow.yml). Din c\u00e2te se pare, atacul nu se limiteaz\u0103 la cele 187 de pachete men\u021bionate, deoarece pe GitHub continu\u0103 s\u0103 apar\u0103 noi repozitorii cu numele Shai-Hulud \u0219i fi\u0219ierul data.json.                    <center><img decoding=\"async\" alt=\"Un vierme auto-replicant a infectat 187 de pachete \u00een NPM\" src=\"\/wp-content\/uploads\/2025\/09\/9192d80585dbe659249741c4365d04aa.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>          <\/p>\n<p>Printre altele, ca urmare a activit\u0103\u021bii viermului, au fost afectate 25 de pachete de la CrowdStrike, care dezvolt\u0103 instrumente pentru <a href=\"https:\/\/prohoster.info\/ro\/zhashchita-ot-ddos\/\"  data-wpil-monitor-id=\"424\">protec\u021bia \u00eempotriva atacurilor<\/a> prin dependen\u021be (Supply Chain). Potrivit CrowdStrike, pachetele compromite nu au fost utilizate pe platforma Falcon iar atacul nu s-a extins la clien\u021bi. De asemenea, s-a aflat c\u0103 valul anterior de publicare a versiunilor mali\u021bioase \u00een NPM, care a avut loc f\u0103r\u0103 vierm, a afectat proiectul gemini-cli, dezvoltat de Google.<br \/>\n<br \/>Sursa: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=63894\">opennet.ro<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0410\u0442\u0430\u043a\u0430 \u043d\u0430 \u0441\u043e\u043f\u0440\u043e\u0432\u043e\u0436\u0434\u0430\u044e\u0449\u0438\u0445 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM \u043f\u0435\u0440\u0435\u0448\u043b\u0430 \u043d\u0430 \u043d\u043e\u0432\u044b\u0439 \u0443\u0440\u043e\u0432\u0435\u043d\u044c. \u0412 \u0434\u043e\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u043a \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044e \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e \u0434\u043b\u044f \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u0430 \u043f\u043b\u0430\u0442\u0435\u0436\u0435\u0439 \u0438 \u043a\u043e\u043d\u0444\u0438\u0434\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0439 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0435 \u043f\u0435\u0440\u0435\u0448\u043b\u0438 \u043a \u0432\u043d\u0435\u0434\u0440\u0435\u043d\u0438\u044e \u0432 \u0441\u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u0447\u0435\u0440\u0432\u044f \u0434\u043b\u044f \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e \u0432 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438. \u041f\u0440\u0438\u043c\u0435\u043d\u0435\u043d\u0438\u0435 \u0447\u0435\u0440\u0432\u044f \u0437\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u043e \u043f\u043e\u0441\u043b\u0435 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 NPM-\u043f\u0430\u043a\u0435\u0442\u0430 @ctrl\/tinycolor, \u0438\u043c\u0435\u044e\u0449\u0435\u0433\u043e 2.2 \u043c\u043b\u043d \u0435\u0436\u0435\u043d\u0435\u0434\u0435\u043b\u044c\u043d\u044b\u0445 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a \u0438 \u0437\u0430\u0434\u0435\u0439\u0441\u0442\u0432\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u043f\u0440\u044f\u043c\u043e\u0439 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":143669,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-143668","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0410\u0442\u0430\u043a\u0430 \u043d\u0430 \u0441\u043e\u043f\u0440\u043e\u0432\u043e\u0436\u0434\u0430\u044e\u0449\u0438\u0445 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM \u043f\u0435\u0440\u0435\u0448\u043b\u0430 \u043d\u0430 \u043d\u043e\u0432\u044b\u0439 \u0443\u0440\u043e\u0432\u0435\u043d\u044c.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/samorasprostranyayushhijsya-cherv-porazil-187-paketov-v-npm\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0421\u0430\u043c\u043e\u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0438\u0439\u0441\u044f \u0447\u0435\u0440\u0432\u044c \u043f\u043e\u0440\u0430\u0437\u0438\u043b 187 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0432 NPM | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0410\u0442\u0430\u043a\u0430 \u043d\u0430 \u0441\u043e\u043f\u0440\u043e\u0432\u043e\u0436\u0434\u0430\u044e\u0449\u0438\u0445 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM \u043f\u0435\u0440\u0435\u0448\u043b\u0430 \u043d\u0430 \u043d\u043e\u0432\u044b\u0439 \u0443\u0440\u043e\u0432\u0435\u043d\u044c.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/samorasprostranyayushhijsya-cherv-porazil-187-paketov-v-npm\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-09-17T09:11:57+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-02-08T19:43:52+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vierme autoreplicant a infectat 187 de pachete \u00een NPM | ProHoster","description":"Atacul asupra pachetelor de asociere \u00een repozitoriul NPM a intrat \u00eentr-o nou\u0103 etap\u0103.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/samorasprostranyayushhijsya-cherv-porazil-187-paketov-v-npm","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0421\u0430\u043c\u043e\u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0438\u0439\u0441\u044f \u0447\u0435\u0440\u0432\u044c \u043f\u043e\u0440\u0430\u0437\u0438\u043b 187 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0432 NPM | ProHoster","og:description":"\u0410\u0442\u0430\u043a\u0430 \u043d\u0430 \u0441\u043e\u043f\u0440\u043e\u0432\u043e\u0436\u0434\u0430\u044e\u0449\u0438\u0445 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM \u043f\u0435\u0440\u0435\u0448\u043b\u0430 \u043d\u0430 \u043d\u043e\u0432\u044b\u0439 \u0443\u0440\u043e\u0432\u0435\u043d\u044c.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/samorasprostranyayushhijsya-cherv-porazil-187-paketov-v-npm","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2025-09-17T09:11:57+00:00","article:modified_time":"2026-02-08T19:43:52+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"143668","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-08 19:43:52","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 14:50:19","updated":"2026-02-08 19:43:52","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/143668","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=143668"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/143668\/revisions"}],"predecessor-version":[{"id":157614,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/143668\/revisions\/157614"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media\/143669"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=143668"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=143668"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=143668"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}