Wednesday, May 20, 2026
  • Login
SB Crypto Guru News- latest crypto news, NFTs, DEFI, Web3, Metaverse
No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS
CRYPTO MARKETCAP
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS
No Result
View All Result
SB Crypto Guru News- latest crypto news, NFTs, DEFI, Web3, Metaverse
No Result
View All Result

GitHub Worm Hits npm Packages With 16M Downloads

by SB Crypto Guru News
May 20, 2026
in Crypto Updates
Reading Time: 4 mins read
0 0
A A
0


Key Takeaways

  • Mini Shai-Hulud exploited GitHub Actions on May 19, compromising 300+ npm packages across 16M weekly downloads.
  • The malware installs a dead-man’s switch that wipes the developer’s machine if the stolen npm token is revoked.
  • GitHub responded May 20 with staged publishing, bulk OIDC onboarding, and a plan to deprecate legacy npm tokens.

Mini Shai-Hulud Exploits GitHub Actions to Hit 16 Million Weekly Downloads

The Mini Shai-Hulud campaign, attributed to the threat group Team PCP, does not work the way most supply chain attacks do because, rather than stealing a developer’s credentials and publishing directly, the attacker forks a target repository on GitHub, opens a pull request that triggers a `pull_request_target` workflow.

This poisons the GitHub Actions cache with a malicious pnpm store, and from that point, the infected packages carry valid signed certificates and pass SLSA provenance checks, making them appear completely clean to standard security tooling.

GitHub Worm Hits npm Packages With 16M Downloads
Image source: X

On May 19, the latest wave struck the AntV data visualization ecosystem as attackers gained access to a compromised maintainer account in the @atool namespace and published more than 300 malicious package versions across 323 packages in a 22-minute automated burst.

Among the affected packages is echarts-for-react, a React wrapper for Apache Echarts with roughly 1.1 million weekly downloads. The collective weekly download count across all affected packages in this wave is estimated at around 16 million.

The most alarming technical detail is what happens if a developer tries to intervene. The malware installs a dead-man’s switch, i.e., a shell script that polls GitHub’s API every 60 seconds to check whether the npm token it created has been revoked. That token carries the description “IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner,” which, if revoked by a developer, immediately wipes the infected machine’s home directory.

The token also steals credentials from GitHub, AWS, Azure, GCP, Kubernetes, Hashi Corp Vault, and over 90 developer tool configurations before spreading laterally across connected cloud infrastructure.

One Attack, Multiple Casualties

The campaign simultaneously hit the Python Package Index (PyPI) as three malicious versions of Microsoft’s official durabletask Python SDK were published on May 19, silently downloading and executing a 28 KB credential-stealing payload (capable of moving across AWS, Azure, and GCP environments after initial execution).

GitHub responded on May 20 with an announcement outlining three core changes to npm publishing, namely bulk OIDC onboarding to help organizations migrate hundreds of packages to trusted publishing at scale, expanded OIDC provider support beyond GitHub Actions and Gitlab, and a new staged publishing model that gives maintainers a review window before packages go live, requiring multi-factor authentication (MFA) approval.

GitHub Worm Hits npm Packages With 16M Downloads
Image source: X

The company also plans to deprecate legacy classic tokens, migrate users to FIDO-based 2FA, and disallow token-based publishing by default. In the earlier wave of the campaign in September 2025, GitHub removed over 500 compromised packages from the npm registry

Blockchain security firm Slowmist had raised an early warning on May 14 after flagging three malicious versions of node-ipc, a package with 822,000 weekly downloads, as part of the same campaign.

Developers using any of the flagged packages have been advised to audit dependency trees immediately, rotate all credentials without revoking the malicious token first, and check indicators of compromise published by Snyk, Wiz, Socket.dev, and Step Security.



Source link

Tags: 16MBitcoin NewsCrypto NewsCrypto UpdatesDownloadsGitHubHitsLatest News on CryptonpmPackagesSB Crypto Guru NewsWorm
Previous Post

OKX’s Gracie Lin Says AI Agents Need Sub-Cent Payments as Bank Rails Slow Tasks

Related Posts

Ripple Just Moved This  Billion Industry Onto The XRP Ledger

Ripple Just Moved This $2 Billion Industry Onto The XRP Ledger

by SB Crypto Guru News
May 20, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure The XRP Ledger is hosting tokenized US...

Turkey’s 8-Day Betting Blitz Hits 670+ Suspects as Crypto Rails Surface in Adana Probe

Turkey’s 8-Day Betting Blitz Hits 670+ Suspects as Crypto Rails Surface in Adana Probe

by SB Crypto Guru News
May 19, 2026
0

Key TakeawaysTwo May 18 operations took legal action against 233 suspects across 20 provinces, citing TL 18 billion ($395 million)...

Market Expert Updates XRP Roadmap To 0 With New Data

Market Expert Updates XRP Roadmap To $300 With New Data

by SB Crypto Guru News
May 19, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Market expert CharuSan has provided an updated...

Bitcoin’s 2028 Halving Countdown Begins as Fewer Than 100,000 Blocks Remain

Bitcoin’s 2028 Halving Countdown Begins as Fewer Than 100,000 Blocks Remain

by SB Crypto Guru News
May 19, 2026
0

Key TakeawaysFewer than 100,034 Bitcoin blocks remain until the halving at block 1,050,000, expected April 2028.The reward will drop from...

Echo Protocol Hack Sparks M Panic After Hacker Mints Fake eBTC and Drains ETH

Echo Protocol Hack Sparks $76M Panic After Hacker Mints Fake eBTC and Drains ETH

by SB Crypto Guru News
May 19, 2026
0

Key Takeaways:A fake eBTC with an estimated value of $76.6 million reportedly caused the theft of the tokens via Echo...

Load More
Facebook Twitter LinkedIn Tumblr RSS

CATEGORIES

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • Mining
  • NFT
  • Regulations
  • Scam Alert
  • Uncategorized
  • Web3

SITE MAP

  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2022 - SB Crypto Guru News.
SB Crypto Guru News is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS

Copyright © 2022 - SB Crypto Guru News.
SB Crypto Guru News is not responsible for the content of external sites.