Science & Health9/10
Microsoft Warns of Mini Shai-Hulud npm Supply Chain Attack
Microsoft Threat Intelligence reports an active npm supply chain attack that compromised maintainer accounts and published credential-stealing packages including keyv and servicetitan packages. The malware self-propagates by republishing infected package versions.
Original post · 1 min read
Microsoft Threat Intelligence is tracking active Mini Shai-Hulud npm supply chain attacks in which a threat actor compromised trusted maintainer accounts to distribute credential-stealing malware.
Compromised packages (confirmed malicious) include:
- keyv@6.0.0
- file-entry-cache@11.1.6
- cache-manager@7.2.10
- cacheable-request@13.0.20
- qlik/api@2.14.2
- cacheable/memory, /utils, /net
- 17+ servicetitan/* packages (eslint-config, anvil-themes, table, form, log-service, etc.)
In this attack, a malicious preinstall hook launches an obfuscated dropper (setup.mjs) that downloads a Bun binary from GitHub and executes a credential-stealing payload, either Math_Symbol.js or Math_Init.js.
The payload is a Mini Shai-Hulud variant, a self-propagating npm supply-chain malware family. It harvests npm, GitHub, cloud and continuous integration (CI) credentials, exfiltrates collected secrets, and uses stolen publishing access to inject itself into package tarballs, increment their versions and republish the compromised releases.
Microsoft observed the same pattern across all affected packages, suggesting a single actor using multiple stolen tokens.
Microsoft Defender for Endpoint customers should act on these alerts: “Trojan:npm/MalBun.A”
Compromised packages (confirmed malicious) include:
- keyv@6.0.0
- file-entry-cache@11.1.6
- cache-manager@7.2.10
- cacheable-request@13.0.20
- qlik/api@2.14.2
- cacheable/memory, /utils, /net
- 17+ servicetitan/* packages (eslint-config, anvil-themes, table, form, log-service, etc.)
In this attack, a malicious preinstall hook launches an obfuscated dropper (setup.mjs) that downloads a Bun binary from GitHub and executes a credential-stealing payload, either Math_Symbol.js or Math_Init.js.
The payload is a Mini Shai-Hulud variant, a self-propagating npm supply-chain malware family. It harvests npm, GitHub, cloud and continuous integration (CI) credentials, exfiltrates collected secrets, and uses stolen publishing access to inject itself into package tarballs, increment their versions and republish the compromised releases.
Microsoft observed the same pattern across all affected packages, suggesting a single actor using multiple stolen tokens.
Microsoft Defender for Endpoint customers should act on these alerts: “Trojan:npm/MalBun.A”
♥ 1.1K · ⟲ 239 · 👁 1.3MView on X ↗
