Shai-Hulud 2.0 NPM malware attack exposed up to 400,000 dev secrets
Summary
The Shai-Hulud 2.0 malware attack has compromised approximately 400,000 raw secrets by infecting numerous packages in the NPM registry and leaking the stolen data across 30,000 GitHub repositories. This incident highlights significant vulnerabilities in software supply chains and the potential risks for developers and organizations relying on these tools.
Original Article Summary
The second Shai-Hulud attack last week exposed around 400,000 raw secrets after infecting hundreds of packages in the NPM (Node Package Manager) registry and publishing stolen data in 30,000 GitHub repositories. [...]
Impact
NPM packages, GitHub repositories
In the Wild
Yes
Timeline
Newly disclosed
Remediation
Developers should audit their NPM packages for vulnerabilities, rotate any exposed secrets, and implement security best practices such as using environment variables for sensitive information.