Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
No Result
View All Result

GitHub Worm Hits npm Packages With 16M Downloads

CryptoExpert by CryptoExpert
May 20, 2026
in Bitcoin News
0
GitHub Worm Hits npm Packages With 16M Downloads
  • Facebook
  • Twitter
  • Pinterest


Key Takeaways

Mini Shai-Hulud exploited GitHub Actions on May 19, compromising 300+ npm packages across 16M weekly downloads.The malware installs a dead-man’s switch that wipes the developer’s machine if the stolen npm token is revoked.GitHub responded May 20 with staged publishing, bulk OIDC onboarding, and a plan to deprecate legacy npm tokens.

Mini Shai-Hulud Exploits GitHub Actions to Hit 16 Million Weekly Downloads

The Mini Shai-Hulud campaign, attributed to the threat group Team PCP, does not work the way most supply chain attacks do because, rather than stealing a developer’s credentials and publishing directly, the attacker forks a target repository on GitHub, opens a pull request that triggers a `pull_request_target` workflow.

This poisons the GitHub Actions cache with a malicious pnpm store, and from that point, the infected packages carry valid signed certificates and pass SLSA provenance checks, making them appear completely clean to standard security tooling.

Tokenmetrics
Image source: X

On May 19, the latest wave struck the AntV data visualization ecosystem as attackers gained access to a compromised maintainer account in the @atool namespace and published more than 300 malicious package versions across 323 packages in a 22-minute automated burst.

Among the affected packages is echarts-for-react, a React wrapper for Apache Echarts with roughly 1.1 million weekly downloads. The collective weekly download count across all affected packages in this wave is estimated at around 16 million.

The most alarming technical detail is what happens if a developer tries to intervene. The malware installs a dead-man’s switch, i.e., a shell script that polls GitHub’s API every 60 seconds to check whether the npm token it created has been revoked. That token carries the description “IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner,” which, if revoked by a developer, immediately wipes the infected machine’s home directory.

The token also steals credentials from GitHub, AWS, Azure, GCP, Kubernetes, Hashi Corp Vault, and over 90 developer tool configurations before spreading laterally across connected cloud infrastructure.

One Attack, Multiple Casualties

The campaign simultaneously hit the Python Package Index (PyPI) as three malicious versions of Microsoft’s official durabletask Python SDK were published on May 19, silently downloading and executing a 28 KB credential-stealing payload (capable of moving across AWS, Azure, and GCP environments after initial execution).

GitHub responded on May 20 with an announcement outlining three core changes to npm publishing, namely bulk OIDC onboarding to help organizations migrate hundreds of packages to trusted publishing at scale, expanded OIDC provider support beyond GitHub Actions and Gitlab, and a new staged publishing model that gives maintainers a review window before packages go live, requiring multi-factor authentication (MFA) approval.

GitHub Worm Hits npm Packages With 16M Downloads
Image source: X

The company also plans to deprecate legacy classic tokens, migrate users to FIDO-based 2FA, and disallow token-based publishing by default. In the earlier wave of the campaign in September 2025, GitHub removed over 500 compromised packages from the npm registry

Blockchain security firm Slowmist had raised an early warning on May 14 after flagging three malicious versions of node-ipc, a package with 822,000 weekly downloads, as part of the same campaign.

Developers using any of the flagged packages have been advised to audit dependency trees immediately, rotate all credentials without revoking the malicious token first, and check indicators of compromise published by Snyk, Wiz, Socket.dev, and Step Security.



Source link

You might also like

Bitcoin MVRV Pattern Predicts Major Downswing Ahead – Details

Bitcoin Short-Term Holders Panic-Sell $770M BTC as Bears Eye $65K

Capital B Buys 192 BTC After $20M Raise as Treasury Strategy Accelerates

  • Facebook
  • Twitter
  • Pinterest
Tags: Bitcoin
CryptoExpert

CryptoExpert

Recommended For You

Bitcoin MVRV Pattern Predicts Major Downswing Ahead – Details

by CryptoExpert
May 20, 2026
0
Bitcoin

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Bitcoin (BTC) is trading around $78,000, as prices continue to fall following another rejection at...

Read more

Bitcoin Short-Term Holders Panic-Sell $770M BTC as Bears Eye $65K

by CryptoExpert
May 19, 2026
0
Cointelegraph

Bitcoin (BTC) price dropped to $76,500 on Monday, erasing nearly all of this month’s gains as fresh US-Iran war tensions soured the crypto market sentiment. This has led...

Read more

Capital B Buys 192 BTC After $20M Raise as Treasury Strategy Accelerates

by CryptoExpert
May 19, 2026
0
Capital B Buys 192 BTC After $20M Raise as Treasury Strategy Accelerates

Key TakeawaysCapital B bought 192 BTC for $15M (€13M), raising total holdings to 3,135 bitcoin.Adam Back backed Capital B’s $20M (€17.15M) raise, signaling rising BTC treasury adoption.Capital B...

Read more

Bitcoin Bleeds $1B Weekly but XRP and SOL Defy Market Panic

by CryptoExpert
May 19, 2026
0
Is Bitcoin's 4-Year Cycle Pure Coincidence? Analysis

Solana, XRP, and Dogecoin attracted fresh investor demand even as Bitcoin and Ethereum experienced sharp institutional selling pressure. Last week, digital asset investment products experienced $1.07 billion...

Read more

Bitcoin Depot, Operator Of 9,000+ ATMs, Files For Bankruptcy Protection

by CryptoExpert
May 18, 2026
0
Bitcoin Depot

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Bitcoin Depot Inc, once the largest operator of Bitcoin ATMs in the world, watched its...

Read more
Next Post
Cointelegraph

World Liberty-Linked AI Financial Flags Going Concern

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

Sitemap

  • Market Cap
  • Donations
  • Trading
  • Mining
  • Contact

Legal Information

  • Privacy Policy
  • Anti-Spam Policy
  • Copyright Notice
  • DMCA Compliance
  • Social Media Disclaimer
  • Terms Of Service

Categories

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

© Copyright 2024 InvestInCryptoNews.com

No Result
View All Result
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO

© Copyright 2024 InvestInCryptoNews.com

This website is using cookies to improve the user-friendliness. You agree by using the website further.

Privacy policy
bitcoin
Bitcoin (BTC) $ 77,343.00
ethereum
Ethereum (ETH) $ 2,127.64
tether
Tether (USDT) $ 0.998925
bnb
BNB (BNB) $ 643.94
xrp
XRP (XRP) $ 1.37
usd-coin
USDC (USDC) $ 0.999703
solana
Solana (SOL) $ 84.88
tron
TRON (TRX) $ 0.356535
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03
staked-ether
Lido Staked Ether (STETH) $ 2,265.05

Pin It on Pinterest

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?