Shai-Hulud malware creeps into Red Hat npm, 80K downloads!

Worm Slithers Into Red Hat’s npm Packages

On Monday, security analysts discovered a cluster of Red Hat npm package releases infested with the mischievous Mini Shai-Hulud worm, unleashed into the wild by TeamPCP cybercriminals. This latest supply chain attack impacted at least 32 npm package releases associated with Red Hat Cloud Services, according to the astute experts from Google-owned Wiz. They traced the malware back to a compromised GitHub account belonging to a Red Hat employee, with the affected packages amassing around 80,000 downloads weekly.

Two Surges of Questionable Activity

The breached account cunningly inserted harmful orphan commits into two RedHatInsights repositories, bypassing the code review, say the threat hunters. This underhanded activity occurred in two surges. Wiz believes this represents a “live threat,” and their researchers are vigilantly monitoring it for any new antics. Meanwhile, Socket recorded 95 affected package versions by 11:00:22 UTC. They’re closely tracking the ongoing assault and refreshing the list of artifacts. If your team or development pipelines have used one of the compromised versions, assume you’re compromised and alter those credentials immediately.

Packed Payload with Impact

The infected versions stealthily execute a hidden payload via a preinstall hook, initiating the malware auto-execution during the npm install process – even before a developer interacts with the package. Socket’s astute examination reveals the payload is designed to pilfer GitHub Actions secrets, npm tokens, cloud credentials, Kubernetes and Vault resources, SSH keys, Git credentials, and other critical information. Additionally, it includes encrypted exfiltration logic and GitHub-based fallback strategies, indicating that the attacker was not only after credentials but also aimed to induce further supply chain chaos.

Red Hat’s Reaction

A Red Hat representative disclosed to GadgetLad that the IBM-owned software entity is aware of the developments. “We initiated an investigation and immediately removed the packages from the npm registry,” the spokesperson stated. “The packages are strictly intended for internal development, and the malicious code never reached customers through the console.redhat.com system. While we’re still investigating, we’ve not observed any impact on customer or partner environments or Red Hat’s production systems.”

Shifting Sandworms

Both security companies assert that the malware resembles the Mini Shai-Hulud worm – however, since TeamPCP made the credential-stealing tool publicly available, pinpointing the blame on TeamPCP or a deceptive copycat group is challenging. According to Wiz, the modifications are largely cosmetic, with references to the Dune universe replaced by Greek mythology themes such as ‘spartan,’ while the core techniques remain unchanged. A noteworthy alteration is that the new variant incorporates data collectors for Google Cloud Platform and Microsoft Azure identities, harvesting all accessible identities on the infected machine, rather than merely stealing secrets from cloud configurations. This indicates “an increased attacker focus on acquiring and exploiting access to the cloud itself,” Wiz cautions.

Miasma and Mayhem

This variant additionally creates repositories branded with the tagline “Miasma: The Spreading Blight.” Unlike previous worm variants that replicated indiscriminately, this crafty one fabricates a unique encrypted payload for each infection, rendering hash-based indicators-of-compromise practically useless for identifying specific package versions.

Summary

Sandworms Unleashed

GadgetLad is here to assist – if you’ve been downloading Red Hat npm packages, you might have acquired more than you intended with the Mini Shai-Hulud worm circulating. Inspect your systems, change credentials, and perhaps monitor your cloud identities closely, lest you provide cybercriminals an extensive view of your sensitive data. Stay safe, everyone!

Visit GadgetLad for more tech antics!