Toutes les vulnérabilités
CRITICALSupply chainexploited in the wild

NPM-SHAI-HULUD-2025

npm · @ctrl/tinycolor, ngx-bootstrap, ng2-file-upload (+500 more)

Résumé

Shai-Hulud was the first self-replicating worm to hit the npm ecosystem, disclosed around September 15, 2025. Beginning with the compromise of @ctrl/tinycolor (over 2 million weekly downloads), the malware harvested developer credentials (npm tokens, GitHub PATs, and AWS/GCP/Azure secrets) using the TruffleHog secret scanner, then automatically authenticated to npm and republished trojanized versions of every package the victim maintained, spreading exponentially without operator intervention. It exfiltrated stolen secrets to attacker webhooks and public GitHub repositories and established persistence via a malicious GitHub Actions workflow. More than 500 packages were ultimately compromised, including several CrowdStrike packages.

Références

Vulnérabilités liées

Tout Supply chain →