Shai Hulud returns wearing a Red Hat


Shai Hulud came for trusted packages

According to reports, attackers compromised npm packages published under Red Hat Cloud Services-related namespace and inserted malware capable of executing automatically during package installation.

The malicious payload was designed to steal a wide range of credentials and secrets from infected environments. Researchers observed attempts to collect npm authentication tokens, environment variables, cloud credentials, and other sensitive information commonly stored on developer workstations and CI/CD systems.

Wiz’s analysis found that the malware belonged to the Mini Shai-Hulud family, a credential-stealing threat that has repeatedly appeared in npm ecosystem attacks throughout the year. “The payload appears to be derived from the (Mini) Shai-Hulud malware open-sourced by TeamPCP,” the researchers said. “The observed modifications are largely cosmetic, with references to the Dune universe replaced by Greek mythology themes (i.e., ‘spartan’), while the underlying functionality and tradecraft remain substantially similar.”

Leave a Reply

Your email address will not be published. Required fields are marked *