Shai Hulud

GitHub、パスワード窃取マルウェアを配布するMicrosoftのリポジトリを無効化 News

GitHub、パスワード窃取マルウェアを配布するMicrosoftのリポジトリを無効化

マイクロソフトは、GitHub上のAzure、microsoft、Azure-Samples、およびMicrosoftDocsの各組織にまたがる73のリポジトリを削除し、継続的インテグレーションのパイプラインに支障をきたした。 この事象は6...
News

新たな「Shai-Hulud」攻撃により、科学分野向けのPyPIパッケージ19件がトロイの木馬化された

ハッカーは、開発者の機密情報を盗むように設計されたマルウェアを配布する新たな「Shai-Hulud」サプライチェーン攻撃により、PyPI上の19のパッケージを侵害しました。これらのパッケージは、合計で数十万回ダウンロードされています。 感染...
Red Hat npm packages compromised to steal developer credentials News

Red Hat npm packages compromised to steal developer credentials

More than 30 npm packages under Red Hat's '@redhat-cloud-services' namespace were compromised in a supply-chain attack t...
Grafana breach caused by missed token rotation after TanStack attack News

Grafana breach caused by missed token rotation after TanStack attack

The Grafana data breach was caused by a single GitHub workflow token that slipped through the rotation process following...
New Shai-Hulud malware wave compromises 600 npm packages News

New Shai-Hulud malware wave compromises 600 npm packages

Threat actors earlier today published more than 600 malicious packages to the Node Package Manager (npm) index as part o...
Leaked Shai-Hulud malware fuels new npm infostealer campaign News

Leaked Shai-Hulud malware fuels new npm infostealer campaign

The Shai-Hulud malware leaked last week is now used in new attacks on the Node Package Manager (npm) index, as infected ...
TeamPCP hackers advertise Mistral AI code repos for sale News

TeamPCP hackers advertise Mistral AI code repos for sale

The TeamPCP hacker group is threatening to leak source code from the Mistral AI project unless a buyer is found for the ...
OpenAI confirms security breach in TanStack supply chain attack News

OpenAI confirms security breach in TanStack supply chain attack

OpenAI says two employees' devices were breached in the recent TanStack supply chain attack that impacted hundreds of np...
Shai Hulud 攻撃、悪意のある TanStack、Mistral npm パッケージを出荷 News

Shai Hulud 攻撃、悪意のある TanStack、Mistral npm パッケージを出荷

開発者を標的とした認証情報を盗むマルウェアを配信する新たな Shai-Hulud サプライチェーンキャンペーンにおいて、npm および PyPI の数百のパッケージが侵害されました。 攻撃者は有効な OpenID Connect (OIDC...
Hackers can bypass npm’s Shai-Hulud defenses via Git dependencies News

Hackers can bypass npm’s Shai-Hulud defenses via Git dependencies

The defense mechanisms that NPM introduced after the 'Shai-Hulud' supply-chain attacks have weaknesses that allow threat...