New Shai-Hulud campaign infects popular npm packages

A new attack campaign, named Shai-Hulud, has compromised at least 26 npm (Node Package Manager) packages with a total of 25 million weekly downloads. Among the infected packages are keyv, keyv-db, keyv-sqlite, keyv-redis, keyv-mssql, keyv-mysql, keyv-postgres, and keyv-leveldb.

Quick Response

  • The Shai-Hulud campaign has infected 26 npm packages with over 25 million weekly downloads
  • The compromised packages include keyv and its extensions for various databases
  • The attack exploits the npm supply chain to distribute malware
  • The main victims are developers using these packages
  • The attack was discovered by Aikido Security

Technical Details of the Attack

The attack was discovered by Aikido Security, which identified a pattern of attack similar to that used in previous campaigns targeting npm packages. The compromised packages were manipulated to include malicious code that performs harmful activities on the systems of developers who install them.

The compromised packages were published with slightly different versions from the originals, exploiting a technique known as "typosquatting" to deceive developers. Once installed, the packages execute malicious code that can include downloading additional payloads, exfiltrating sensitive data, or installing backdoors.

Impact on Developer Security

The main impact of this attack campaign is on the community of developers using npm for package management. Developers who have installed the compromised versions of the packages may have already suffered damage to their system or exposed their sensitive data.

Additionally, developers using these packages in their projects may have inadvertently distributed the malicious code to their end users, thus expanding the impact of the attack.

Security Community Response

The cybersecurity community has responded promptly to the discovery of this attack campaign. Aikido Security has published a detailed report on the attack, providing indicators of compromise and mitigation recommendations.

Furthermore, the maintainers of the compromised packages have acted quickly to remove the harmful versions and release new clean versions. Developers are advised to verify the versions of the packages they use and update to the latest and safest versions.

Tips for Developers

To mitigate the risk of similar attacks, developers are advised to follow best security practices when using npm packages. This includes:

  • Verifying the authenticity of packages before installing them
  • Using security analysis tools to identify malicious packages
  • Regularly updating packages to ensure they have the latest and safest versions
  • Monitoring security community communications to stay informed about new threats

Implications for Supply Chain Security

This attack underscores the importance of supply chain security in the context of software development. Supply chain attacks can have a significant impact on the security of developers and their end users and require a proactive approach for mitigation.

Organizations that develop software should consider implementing advanced security measures to protect their supply chain, such as using automated security analysis tools and conducting regular security audits.

Analysis of Attackers' Tactics

Aikido Security analysts have noted that the attackers behind Shai-Hulud have adopted a sophisticated methodology, combining various evasion and persistence techniques. Among these, the following stand out:

  • The use of obfuscated code to make static analysis difficult
  • The implementation of timers to delay the execution of the malicious payload
  • The creation of fake dependency packages to confuse analysis tools

These techniques suggest that the aggressors have an in-depth knowledge of JavaScript/Node.js development ecosystems and common security practices among developers.

Malware Distribution Techniques

The malware distribution occurs through a multi-phase mechanism:

  1. Installation of the compromised package
  2. Execution of an environment check to avoid test/sandbox environments
  3. Download of the main payload from remote servers
  4. Execution of the payload with elevated privileges

Particularly concerning is the use of legitimate CDNs (Content Delivery Networks) to host secondary payloads, making it more difficult to block malicious communications.

Implications for Open Source Ecosystems

This attack raises important questions about:

  • The sustainability of open-source package maintenance
  • The need for economic models to support security
  • The importance of diversifying dependencies

The case of keyv demonstrates how even seemingly simple packages can become critical points in the development supply chain.

Advanced Mitigation Measures

In addition to standard practices, experts recommend:

  • The implementation of isolated build sandboxes
  • The use of dynamic analysis tools such as Docker Scout
  • The adoption of multi-factor approval policies for dependencies
  • The integration of runtime behavior monitoring solutions

Organizations should consider adopting frameworks like SLSA (Supply-chain Levels for Software Artifacts) to improve supply chain security.

Similar Case Studies

This attack reminds us of previous campaigns such as:

  • UA-17581541-1
  • Coverage insurance for supply chain attacks
  • Compliance with standards such as ISO 27001 and NIST SP 800-218

Organizations should review their risk management policies in light of these developments.

Future Perspectives

Experts predict that:

  • Supply chain attacks will become more frequent
  • Developers will need to adopt more rigorous security practices
  • Platforms like npm will implement stricter controls

This incident could accelerate the adoption of more secure development practices at the industrial level.

Open Questions

The security community is still investigating:

  • The identity of the aggressors
  • The full scope of the infection
  • The possible connection with other recent attacks

These questions remain open as investigations continue.

The Shai-Hulud attack represents an important reminder of the need for robust supply chain security in software development. While the community responds quickly, developers must adopt more secure practices to protect their projects and end users.

Collaboration between maintainers, platforms, and developers will be crucial to mitigating future threats in this space.

Additional Resources

To stay updated on the latest threats and solutions:

  • Subscribe to the [Daily Briefing](https://thecyberwire.com/newsletters/daily-briefing) newsletter
  • Follow CyberWire Daily on [LinkedIn](https://www.linkedin.com/company/10454826/admin/feed/posts/)
  • Explore security resources on [aikido.dev](https://www.aikido.dev/)

These resources offer valuable information for navigating the complex landscape of cybersecurity.

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication or an editorial product under Law No. 62/2001 and does not provide real-time information.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all responsibility for the improper use of the information published.

In the Crypto sector, every investment involves risks: readers are advised to always inform themselves independently before making any decisions.