Back Bitget SlowMist detects high-risk npm worm "Mini Shai-Hulud", capable of stealing CI/CD keys and ...
According to ChainCatcher, blockchain security firm SlowMist (@SlowMist_Team) has reported that its threat monitoring system MistEye has detected a highly sophisticated npm worm named “Mini Shai-Hulud” spreading through popular developer projects such as TanStack, UiPath, and DraftLab. Attackers hijack GitHub credentials to publish malicious packages disguised as legitimate updates, embedding a hidden script called router_init.js that runs silently in GitHub Actions and other CI/CD environments. This script is designed to steal CI/CD keys, cloud infrastructure keys, and cryptocurrency wallet information, and exfiltrates data using GitHub’s own infrastructure.
SlowMist has already shared the relevant threat intelligence (IOC) with its clients. Projects using affected packages are advised to immediately check their CI/CD pipelines for the presence of the router_init.js file, rotate all exposed GitHub, cloud service, and cryptocurrency credentials, and continuously monitor their development environments for suspicious background activity.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
New York Fed: U.S. consumer loan delinquency rates remain high but have not worsened
Spot Gold Extends Intraday Losses to 2%, Now Trading at $4640.33 per Ounce
JPMorgan warns of UK political turmoil: may reconsider London headquarters investment if a bank tax increase is imposed
WLFI: Token unlock schedule is now live, users can activate their remaining token allocations
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
