Journey Planner UK Train Route Planner

package security

Later, the researcher warned that the secrets stolen in the supply-chain attack were leaked on GitHub. The threat actor automatically downloaded legitimate packages, modified the package.json file to inject a malicious script, and then https://elitecolumbia.com/businessware-technologies-offers-a-full-range-of-services-from-initial-consulting-to-development-and-implementation.html published them on npm using compromised maintainer accounts. The malicious packages have been added to NPM (Node Package Manager) over the weekend to steal developer and continuous integration and continuous delivery (CI/CD) secrets. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document.

This aligns with other recent campaigns where compromised npm packages or GitHubActions exfiltrated CI secrets at massive scale. The https://residenzpflicht.info/the-10-best-resources-for-3/ malware doesn’t go after random consumer data. Build scripts are an execution environment. Instead of publishing lookalike packages, the attackers targeted abandoned but trusted packages, inheriting users and reputation in one move.

It scrapes GitHub Actions runner memory directly to pull masked secrets out in unmasked form, the same technique observed in the TanStack compromise from May 2026. Once active, the malware operates as a comprehensive credential harvester purpose-built for CI/CD environments, targeting AWS keys, GCP credentials, Azure tokens, HashiCorp Vault tokens, GitHub Actions secrets, and 1Password vaults. The malicious root index.js weighs 4.5 MB while the legitimate package entry point is only 27 KB, a size gap that should raise immediate suspicion. The attacker embedded a shell command using gyp’s own command substitution syntax, silently launching a malicious payload while returning a fake source filename so the build shows no errors. The payload is a new variant of the Miasma worm, a self-spreading supply chain malware family that had already hit 32 packages under the @redhat-cloud-services npm namespace just two days earlier.

package security

Our app gives you complete control from anywhere

  • Namely, it uses the open-source tool TruffleHog to search for exposed credentials and access tokens on the developer’s machine.
  • Vivint is committed to making home automation accessible and affordable through innovative state-of-the-art products, customizable packages, and flexible financing.
  • “On June 15, 2026, Federal Protective Service was conducting a sweep of a publicly accessible lobby at a ICE office building in Brooklyn Heights, Ohio. During the sweep, a K-9 alerted to a suspicious package in a UPS drop box,” a spokesperson said.
  • Enumerate Arch and Arch-derivative systems in your environment (laptops, lab machines, self-hosted CI runners).
  • Within an hour, more than 50 additional packages belonging to the maintainer jagreehal were also poisoned, including ai-sdk-ollama, which counts more than 120,000 monthly downloads.

It also found the entire attack design assumes the victim is working in a Linux or macOS environment, and that it deliberately skips Windows systems. A writeup on the attack from StepSecurity found that for cloud-specific operations, the malware enumerates AWS, Azure and Google Cloud Platform secrets. “These packages are not used in the Falcon sensor, the platform is not impacted and customers remain protected,” the statement reads, referring to the company’s widely-used endpoint threat detection service. Namely, it uses the open-source tool TruffleHog to search for exposed credentials and access tokens on the developer’s machine. Last month’s attack on nx did not self-propagate like a worm, but this Shai-Hulud malware does and bundles reconnaissance tools to assist in its spread.

North Korea-Linked Hackers Hide JavaScript Loaders in Open Source Repositories

  • A beginner’s guide to home automation, with tips to build your smart home system step by step, plus a pro option for hassle-free setup.
  • The attackers targeted other package maintainers and developers using the same email, according to reports from those who received the phishing message.
  • Arch Linux on Monday announced that it has suspended new account registrations on the Arch User Repository (AUR) in response to a wave of malicious packages being published as part of an ongoing supply chain attack.
  • CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document.
  • For more information, visit the developer’s accessibility website .

Thermal night vision system from FLIR displays heat signatures as well as standard night vision. A quick access built-in safe can hold valuables or protective equipment. Magnetic dead-bolts and electrified door handles provide maximum security against unauthorized or forceful access. EMP weapons are also used to disable electrical systems prior to a broader attack. A power 6.2L V8 is standard and a 6.2L Supercharged V8 as optional

package security

“It is the expansion of the campaign into another legitimate open source maintainer scope, this time involving Backstage plugins that sit close to internal developer portals, source-control integrations, and authentication workflows.” It’s suspected that the compromise of the “codfish/semantic-release-action” GitHub Action may have been the upstream access path that enabled the attacker to gain access to publish malicious @immobiliarelabs package versions. That having said, the attack employs the same Miasma execution pattern observed in malicious npm packages without relying on native Go module resolution or build logic. “A compromise here can expose developer workstations, CI/CD systems, AWS-backed applications, GitHub repositories, package publishing credentials, and downstream package consumers.” The malware, besides featuring a Russian locale killswitch and checking for the presence of endpoint security software, drops a workflow named “Run Copilot” to capture CI/CD environment secrets from the runner memory. The end goal of the campaign, as before, is to harvest developer or maintainer credentials and weaponize the stolen data to spread across package registries, repositories, and trusted developer workflows.

package security

How much does Vivint cost?

package security

While conventional npm malware operates with one to three execution stages, Shai-Hulud deploys a six-stage payload delivery chain that loops back on itself in an endless execution cycle. At least 187 code packages made available through the JavaScript repository NPM have been infected with a self-replicating worm that steals credentials from developers and publishes those secrets on GitHub, experts warn. Upon learning of the compromise, Red Hat promptly launched an investigation, revoked compromised user and automation tokens, removed the malicious registry packages, corrected the push protection infrastructure, and initiated forensic endpoint isolation. The payload is tuned for developers and CI. An attacker who compromises a single Arch-based developer laptop can still pivot into GitHub, npm, or cloud accounts that power non-Arch production systems. The malicious npm package masquerading as atomic-lockfile contains a credential-stealing payload written in Rust, with optional rootkit-like capabilities on systems where it gains root.

  • Wiz researchers recommend security teams to first identify the compromised packages and replace them with legitimate ones.
  • North Korean hackers are targeting open source software developers with a backdoor and an information stealer as part of a broad supply chain campaign, Socket reports.
  • Cortex Cloud AppSec detects exposed credentials (secrets) and validates whether they are still active, enabling teams to rotate compromised tokens before they are weaponized.
  • Without a Vivint services plan, product and system functionality is limited (including loss of remote connectivity).
  • Catalog of official Microsoft MCP (Model Context Protocol) server implementations for AI-powered data access and tool integration
  • Check Point doesn’t require an MTA, proxy, or agent, so there is nothing for you or your end users to install.

Unpinned GitHub Actions Detection Tag poisoning, the core delivery mechanism of the attack, would have been neutralized if downstream users pinned GitHub Actions to full SHA hashes instead of mutable version tags. No single security control can stop a sophisticated supply chain attack. The malicious commits reused original author metadata and timestamps, creating a deceptive appearance in Git history. The attackers, a group identifying as TeamPCP (also tracked as DeadCatx3, PCPcat, ShellForce, and CipherForce), retained access to the credentials that survived. The breach exposed CI/CD secrets, planted persistent backdoors on developer machines, and spread a self-propagating worm across dozens of npm packages. Aqua Security’s Trivy, one of the most widely used open-source vulnerability scanners, was compromised in a multi-phase supply chain attack.

Leave a Comment