A 710 KB JavaScript payload was discovered in the compromised keyv@6.0.0 package, representing a newer variant of Shai-Hulud with enhanced obfuscation techniques. The malicious code operates with four primary objectives: harvesting credentials from local systems, CI environments, cloud platforms, Kubernetes, and Vault; exfiltrating encrypted data through dynamic HTTPS endpoints or public GitHub repositories; leveraging stolen npm credentials to publish infected patch releases across accessible packages; and exploiting GitHub credentials with GitHub Actions to compromise repositories and extract additional credentials. The campaign demonstrates sophisticated supply chain attack capabilities, targeting the npm ecosystem and development infrastructure. Multiple components were identified including obfuscated JavaScript files, VS Code configuration files, and injected GitHub Actions workflows, indicating a comprehensive approach to credential theft and lateral movement across development environments.
Created: 2026-08-06
類似するPulseは見つかりませんでした。
このPulseに見つかったCVEはありません。