An ongoing supply chain attack has compromised multiple npm packages published by CrowdStrike, extending a malicious campaign known as the “Shai-Halud attack.”
The incident, which involves the same malware previously used to target the popular tinycolor package, highlights the persistent threat of supply chain vulnerabilities within the open-source ecosystem.
The npm registry acted swiftly to remove the affected packages, but developers and organizations are urged to take immediate action to mitigate potential damage.
The compromise originated from the crowdstrike-publisher npm account and has been identified as a continuation of the Shai-Halud supply chain campaign.
The malware deployed is identical to the one observed in the tinycolor incident, indicating a consistent modus operandi by the threat actors.
The core of the attack is a malicious bundle.js script embedded within the compromised packages. Once executed, this script initiates a multi-stage process designed to steal sensitive credentials and establish persistence within victim environments.
According to Socket, the script begins by downloading and running TruffleHog, a legitimate open-source tool designed to scan for secrets and credentials.
By leveraging a trusted tool, the attackers attempt to evade detection while they search the host system for valuable assets like API tokens and cloud credentials.
Once discovered, these secrets are validated to ensure they are active. The malware then creates unauthorized GitHub Actions workflows in compromised repositories, enabling the attackers to maintain access and automate further malicious activities. All exfiltrated data is sent to a hardcoded webhook endpoint controlled by the attackers.
A significant number of packages and specific versions were compromised in this attack, spanning a range of CrowdStrike’s development tools, Socket said.
The affected packages include multiple versions of @crowdstrike/commitlint, @crowdstrike/glide-core, @crowdstrike/logscale-dashboard, and eslint-config-crowdstrike, among others.
| Package Name | Affected Version(s) |
|---|---|
@crowdstrike/commitlint | 8.1.1, 8.1.2 |
@crowdstrike/falcon-shoelace | 0.4.2 |
@crowdstrike/foundry-js | 0.19.2 |
@crowdstrike/glide-core | 0.34.2, 0.34.3 |
@crowdstrike/logscale-dashboard | 1.205.2 |
@crowdstrike/logscale-file-editor | 1.205.2 |
@crowdstrike/logscale-parser-edit | 1.205.1, 1.205.2 |
@crowdstrike/logscale-search | 1.205.2 |
@crowdstrike/tailwind-toucan-base | 5.0.2 |
The SHA-256 hash of the malicious bundle.js file has been identified as 46faab8ab153fae6e80e7cca38eab363075bb524edd79e42269217a083628f09.
A CrowdStrike spokesperson told Cybersecuritynews, “After detecting several malicious Node Package Manager (NPM) packages in the public NPM registry, a third-party open source repository, we swiftly removed them and proactively rotated our keys in public registries.”
“These packages are not used in the Falcon sensor, the platform is not impacted and customers remain protected. We are working with NPM and conducting a thorough investigation.”
Organizations are strongly advised to conduct thorough audits of CI/CD pipelines, developer laptops, and any other environments where the malicious packages may have been installed.
Any npm tokens or other secrets exposed on these systems should be rotated immediately. Furthermore, continuous monitoring of logs for unusual npm publish events or unauthorized package modifications is crucial to detect any follow-on activity.
Also Read
SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route…
ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real…
WhatsApp has confirmed that more than 1 billion people now use passkeys to log into…
ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…
A near-autonomous cyberattack using open-source AI agent frameworks compromised government systems in Asia, cracked 85…
A new web-based scam is using fake Microsoft-branded security scans to frighten people into removing…