xploitzone.com • 3h
Shai-Hulud: npm and PyPI Cross-Ecosystem Worm
The Shai-Hulud (ChainDrop) campaign, attributed to TeamPCP, employs a self-propagating worm targeting the npm and PyPI ecosystems. By compromising npm packages such as openapi-react-query, the malware exfiltrates environment variables and registry API tokens from developer workstations. It uniquely implements a cross-ecosystem pivot, utilizing stolen PyPI tokens to autonomously publish malicious Python packages, creating a recursive infection loop. This campaign affected over 400 npm packages with an aggregate reach of 59 million monthly downloads, demonstrating a scalable, automated supply chain attack vector that bypasses traditional static trojan limitations through autonomous credential harvesting and republishing.
Links:xploitzone.com, Falconfeeds, Blog, Cyberalchemy, Socprime, Endorlabs, Reversinglabs, Expel, Elastic •