Shai Hulud and Looking Into the Deep End of Supply Chain Mayhem
abdulmhsblog.com | blog | #supply-chain | #credential-theft | #npm | #malware-analysis | #backdoor | #worm | #shai-hulud
Summary
Analysis of the leaked Shai-Hulud npm supply chain worm: credential harvesting, exfiltration via C2 or GitHub, backdooring with stolen npm tokens, and a deadman switch that wipes the home directory.
- Published
- Collected
Skip to content