Cybersecurity firm SlowMist has detected a high-risk npm worm, dubbed "Mini Shai-Hulud," that is actively targeting cryptocurrency information. The worm spreads through projects like TanStack and UiPath by hijacking GitHub credentials to publish malicious packages. It is designed to steal CI/CD keys, cloud service credentials, and cryptocurrency wallet information.
SlowMist advises affected projects to inspect the router_init.js file for signs of compromise, rotate any exposed credentials, and maintain vigilance for suspicious activity. This proactive approach is crucial to mitigate the risks posed by this malicious software.
SlowMist Identifies High-Risk npm Worm Targeting Crypto Data
Aviso legal: El contenido de Phemex News es únicamente informativo.No garantizamos la calidad, precisión ni integridad de la información procedente de artículos de terceros.El contenido de esta página no constituye asesoramiento financiero ni de inversión.Le recomendamos encarecidamente que realice su propia investigación y consulte con un asesor financiero cualificado antes de tomar cualquier decisión de inversión.
