top of page
perceptive_background_267k.jpg

GitLab discovers widespread npm supply chain attack

Published:

24 november 2025 om 00:00:00

Alert date:

5 december 2025 om 08:03:23

Source:

gitlab.com

Click to open the original link from this advisory

GitLab discovered a widespread npm supply chain attack involving an evolved version of the Shai-Hulud malware. The malware harvests credentials from GitHub, npm, AWS, GCP, and Azure, then propagates by automatically infecting other packages owned by victims. Most critically, it contains a 'dead man's switch' mechanism that destroys user data if its propagation channels are severed. The attack uses stolen tokens to create GitHub repositories as data exfiltration points and spreads through npm packages via malicious preinstall scripts. The worm-like propagation creates a resilient botnet-like network where compromised systems share access tokens.

Technical details

Mitigation steps:

Affected products:

npm
GitHub
AWS
GCP
Azure
GitLab

Related links:

Related CVE's:

Related threat actors:

IOC's:

bun_environment.js, .truffler-cache/, .truffler-cache/extract/, .truffler-cache/trufflehog, .truffler-cache/trufflehog.exe, del /F /Q /S "%USERPROFILE%*", shred -uvz -n 1, cipher /W:%USERPROFILE%, curl -fsSL https://bun.sh/install | bash, powershell -c "irm bun.sh/install.ps1|iex", Sha1-Hulud: The Second Coming., setup_bun.js

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page