SecurityHorrors

Stories you never want to feel on your own skin

Mini Shai-Hulud: 639 Packages Deep and Still Burrowing

Andras Bacsai's avatar
Mini Shai-Hulud: 639 Packages Deep and Still Burrowing

Sources:


tldr: The Mini Shai-Hulud supply-chain campaign is back with another wave. Around 639 npm packages are now confirmed compromised, including over 275 packages in the antv family and echarts-for-react. Same worm, bigger reach — check your lockfiles.

Affected packages

What to do

  • Check your lockfiles and dependency trees against the full affected package list.
  • Review Socket’s Indicators of Compromise to determine if your environments were hit.
  • Remove affected versions and upgrade to clean releases.
  • Rotate tokens and credentials on any machine or CI runner that installed an affected package.
  • Audit GitHub tokens, npm publishing tokens, cloud credentials, and other secrets as in the previous wave.