Shai-Hulud 2.0 doesn't just propagate like a typical trojan – it behaves like a full-blown worm. Once a compromised package is installed, the malware can steal not only npm or GitHub tokens, but also cloud credentials (AWS, Azure, GCP), CI/CD secrets, environment variables, and other sensitive data from developer machines or build systems.
from https://www.theregister.com.
View original post.
Comments
Post a Comment