SlowMist 检测到高危 npm 蠕虫,“Mini Shai-Hulud”,可窃取 CI/CD 密钥及加密钱包信息

链捕手
May 12

ChainCatcher 消息,据区块链安全机构 SlowMist (@SlowMist_Team) 旗下威胁监控系统 MistEye 监测,一款名为 “Mini Shai-Hulud” 的高度复杂 npm 蠕虫正通过 TanStack、UiPath、DraftLab 等知名开发者项目传播。攻击者劫持 GitHub 凭证,发布伪装成合法更新的恶意软件包,并在其中植入隐藏脚本 router_init.js,在 GitHub Actions 等 CI/CD 环境中静默运行,专门窃取 CI/CD 密钥、云基础设施密钥及加密货币钱包信息,并借助 GitHub 自身基础设施进行数据外传。

SlowMist 已向客户同步相关威胁情报 (IOC),建议使用受影响软件包的项目立即排查 CI/CD 管道中是否存在 router_init.js 文件,轮换所有已暴露的 GitHub、云服务及加密货币凭证,并持续监控开发环境中的异常后台活动。

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10