Information security
fromSecurityWeek
6 days agoTeamPCP Ups the Game, Releases Shai-Hulud Worm's Source Code
Released Shai-Hulud worm source code enables copycat supply-chain attacks and rapid creation of malware variants.
A new version of the Shai-Hulud credentials-stealing self-propagating worm is expanding through the open npm registry, a threat that developers who download packages from the repository have to deal with immediately. Researchers at Wiz Inc. said Monday that in the early stages of the campaign late last week,a thousand new GitHub repositories containing harvested victim data were being added every 30 minutes. And researchers at JFrog identified 181 compromised packages.