Shai-Hulud Malware Campaign Targets npm Packages, Affecting Millions
A new malware campaign, dubbed Shai-Hulud, has compromised over 440 npm packages, affecting more than 2 billion monthly downloads. The malware, which spreads through npm's preinstall scripts, targets popular packages like Keyv and Cacheable. It exfiltrates data using stolen GitHub tokens and contains a dead man's switch to delete data if the token is revoked. The campaign highlights vulnerabilities in npm's security, as the malware persists through local AI agents and IDEs. Developers are advised to rotate keys, enable two-factor authentication, and downgrade affected packages.