thehackernews.com • 14w
Multi-Vector Supply Chain Campaign: Mastra AI, GitHub Actions, and Arch Linux AUR Compromise
A sophisticated supply chain campaign, attributed to the suspected threat actor TeamPCP, has simultaneously targeted the Mastra AI framework via npm, GitHub Actions CI/CD workflows, and the Arch Linux User Repository (AUR). The attack utilized dormant contributor account takeovers to poison the @mastra npm scope using the easy-day-js dependency and hijacked GitHub Action version tags to exfiltrate CI/CD credentials. Additionally, over 1,500 AUR packages were compromised with eBPF-based rootkit malware. This coordinated infrastructure, linked by the "Mini Shai-Hulud" worm, facilitates widespread code execution, credential theft, and persistent rootkit deployment across development, DevOps, and end-user Linux environments.
Links:thehackernews.com, Armorcode, Safestate, Bankinfosecurity, Security Affairs, cyberinsider.com, Infosecurity-magazine, techjacksolutions.com, arXiv (Computer Science - Cryptography and Security), Cybersecurity News, gbhackers.com, threat-modeling.com, appsec.fyi, Microsoft Security Blog, penligent.ai, DEV Community, Hexnode Blog, threatlocker.com, Labs, Privacyguides, +58 more → •