Over 300 npm packages attacked by self-replicating worm – Serious security warning

Over 300 npm packages, including tinycolor and CrowdStrike packages, have been infected by the self-replicating worm Shai-Hulud. Learn how it works, which packages are affected, and what you can do to protect your projects.

The programming community was shocked when it was discovered that the tinycolor package – a hugely popular color manipulation library on npm (over 2 million downloads per week) – had been hacked, taking down over 40 other packages. However, the incident did not stop there: researchers at Socket have just announced that a self-propagating worm has infected over 300 npm packages.

 

How it spreads

The attackers inserted a malicious function called NpmModule.updatePackage into the compromised libraries. This function automates the entire infection process:

  1. Download the tarball of the target package.
  2. Edit the package.json file .
  3. Inject the malicious script bundle.js .
  4. Repackage it, then publish it to npm with the stolen token.

In addition, this worm also has the behavior of searching for environment variables such as NPM_TOKEN to get login information, from there continuing to spread to other packages maintained by the same account.

 

CrowdStrike was also affected.

According to Socket, CrowdStrike's npm account was also compromised, infecting many of its packages with malicious code. CrowdStrike has since removed the affected packages and changed all login credentials.

The campaign has been dubbed Shai-Hulud – inspired by the 'giant sandworm' from the science fiction novel Dune . The name comes from workflow files named shai-hulud.yaml in the malware.

The attack payload is considered quite sophisticated. It uses TruffleHog – a legitimate secret scanning tool – to find and validate credentials, before sending them to the attacker's server via webhook.

Some prominent infected packages include:

  • @ctrl/tinycolor
  • ngx-toastr
  • @crowdstrike/glide-core
  • angulartics2
  • eslint-config-crowdstrike
  • @nativescript-community/ui-collectionview

If affected, users need to Remove the malicious package immediately:

npm uninstall

Fix the secure version until a patch is available:

npm install @ --save-exact

In addition, it is necessary to change all login information on the system because this worm is capable of stealing sensitive data, including: NPM tokens, GitHub Personal Access Tokens & Actions Secrets, SSH keys, Cloud login information (AWS, Google Cloud, Azure), API keys, database connection strings, secrets stored in AWS Secrets Manager and similar services.

Close
Category

System

Windows XP

Windows Server 2012

Windows 8

Windows 7

Windows 10

Wifi tips

Virus Removal - Spyware

Speed ​​up the computer

Server

Security solution

Mail Server

LAN - WAN

Ghost - Install Win

Fix computer error

Configure Router Switch

Computer wallpaper

Computer security

Mac OS X

Mac OS System software

Mac OS Security

Mac OS Office application

Mac OS Email Management

Mac OS Data - File

Mac hardware

Hardware

USB - Flash Drive

Speaker headset

Printer

PC hardware

Network equipment

Laptop hardware

Computer components

Advice Computer

Game

PC game

Online game

Mobile Game

Pokemon GO

information

Technology story

Technology comments

Quiz technology

New technology

British talent technology

Attack the network

Artificial intelligence

Technology

Smart watches

Raspberry Pi

Linux

Camera

Basic knowledge

Banking services

SEO tips

Science

Strange story

Space Science

Scientific invention

Science Story

Science photo

Science and technology

Medicine

Health Care

Fun science

Environment

Discover science

Discover nature

Archeology

Life

Travel Experience

Tips

Raise up child

Make up

Life skills

Home Care

Entertainment

DIY Handmade

Cuisine

Christmas

Application

Web Email

Website - Blog

Web browser

Support Download - Upload

Software conversion

Social Network

Simulator software

Online payment

Office information

Music Software

Map and Positioning

Installation - Uninstall

Graphic design

Free - Discount

Email reader

Edit video

Edit photo

Compress and Decompress

Chat, Text, Call

Archive - Share

Electric

Water heater

Washing machine

Television

Machine tool

Fridge

Fans

Air conditioning

Program

Unix and Linux

SQL Server

SQL

Python

Programming C

PHP

NodeJS

MongoDB

jQuery

JavaScript

HTTP

HTML

Git

Database

Data structure and algorithm

CSS and CSS3

C ++

C #

AngularJS

Mobile

Wallpapers and Ringtones

Tricks application

Take and process photos

Storage - Sync

Security and Virus Removal

Personalized

Online Social Network

Map

Manage and edit Video

Data

Chat - Call - Text

Browser and Add-on

Basic setup