Close Menu
  • Home
  • AI
  • Big Data
  • Cloud Computing
  • iOS Development
  • IoT
  • IT/ Cybersecurity
  • Tech
    • Nanotechnology
    • Green Technology
    • Apple
    • Software Development
    • Software Engineering

Subscribe to Updates

Get the latest technology news from Bigteetechhub about IT, Cybersecurity and Big Data.

    What's Hot

    Thinking Machines Lab inks massive compute deal with Nvidia

    March 10, 2026

    The data behind the win: How Catapult and AWS IoT are transforming pro sports

    March 10, 2026

    Next Generation, Permanent DNA-Based Data Storage for the AI Age

    March 10, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Big Tee Tech Hub
    • Home
    • AI
    • Big Data
    • Cloud Computing
    • iOS Development
    • IoT
    • IT/ Cybersecurity
    • Tech
      • Nanotechnology
      • Green Technology
      • Apple
      • Software Development
      • Software Engineering
    Big Tee Tech Hub
    Home»Cloud Computing»New Shai-Hulud worm spreading through npm, GitHub
    Cloud Computing

    New Shai-Hulud worm spreading through npm, GitHub

    big tee tech hubBy big tee tech hubNovember 25, 2025011 Min Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
    Follow Us
    Google News Flipboard
    New Shai-Hulud worm spreading through npm, GitHub
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link



    4095604 0 00165400 1764030281 shutterstock 2321046757 71010c

    Shai-Hulud first emerged in September, revealed by the discovery that dozens of npm libraries, including a color library with over 2 million downloads a week, had been replaced with malicious versions.

    The initial Shai-Hulud wave was already one of the most severe JavaScript supply-chain attacks Wiz has seen, Merav Bar, a company threat researcher and co-author of the report told CSO. “This new wave is bigger and faster: more than 25,000 attacker-created repos across roughly 350 GitHub users, growing by about 1,000 repos every 30 minutes, with malware that steals developer and cloud credentials and runs in the preinstall phase, touching dev machines and CI/CD pipelines alike. That combination of scale, speed, and access makes it a high-impact campaign.”

    Assume compromise

    If an individual had pulled any of the affected packages during the November 21–23 window, she said, they should assume their environment is exposed. Remedies include clearing the npm cache on their workstation, removing node_modules, reinstalling from clean versions, or pinning to versions published before the malicious releases, and rotating any tokens or secrets that were present (GitHub PATs, npm tokens, SSH keys, cloud credentials).



    Source link

    GitHub npm ShaiHulud spreading Worm
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    tonirufai
    big tee tech hub
    • Website

    Related Posts

    Prompt injection is the new SQL injection, and guardrails aren’t enough

    March 10, 2026

    Native Splunk Integration in Cisco Nexus One: Real-Time Insights

    March 9, 2026

    CSP: Future-Proof Growth: Beyond Basic Hosting: 5 VCF Deployment Models

    March 8, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Thinking Machines Lab inks massive compute deal with Nvidia

    March 10, 2026

    The data behind the win: How Catapult and AWS IoT are transforming pro sports

    March 10, 2026

    Next Generation, Permanent DNA-Based Data Storage for the AI Age

    March 10, 2026

    ChatGPT as a therapist? New study reveals serious ethical risks

    March 10, 2026
    About Us
    About Us

    Welcome To big tee tech hub. Big tee tech hub is a Professional seo tools Platform. Here we will provide you only interesting content, which you will like very much. We’re dedicated to providing you the best of seo tools, with a focus on dependability and tools. We’re working to turn our passion for seo tools into a booming online website. We hope you enjoy our seo tools as much as we enjoy offering them to you.

    Don't Miss!

    Thinking Machines Lab inks massive compute deal with Nvidia

    March 10, 2026

    The data behind the win: How Catapult and AWS IoT are transforming pro sports

    March 10, 2026

    Subscribe to Updates

    Get the latest technology news from Bigteetechhub about IT, Cybersecurity and Big Data.

      • About Us
      • Contact Us
      • Disclaimer
      • Privacy Policy
      • Terms and Conditions
      © 2026 bigteetechhub.All Right Reserved

      Type above and press Enter to search. Press Esc to cancel.