Cybersecurity firm SlowMist has detected a high-risk npm worm, dubbed "Mini Shai-Hulud," that is actively targeting cryptocurrency information. The worm spreads through projects like TanStack and UiPath by hijacking GitHub credentials to publish malicious packages. It is designed to steal CI/CD keys, cloud service credentials, and cryptocurrency wallet information.
SlowMist advises affected projects to inspect the router_init.js file for signs of compromise, rotate any exposed credentials, and maintain vigilance for suspicious activity. This proactive approach is crucial to mitigate the risks posed by this malicious software.
SlowMist Identifies High-Risk npm Worm Targeting Crypto Data
Avertissement : Le contenu proposé sur Phemex News est à titre informatif uniquement. Nous ne garantissons pas la qualité, l'exactitude ou l'exhaustivité des informations provenant d'articles tiers. Ce contenu ne constitue pas un conseil financier ou d'investissement. Nous vous recommandons vivement d'effectuer vos propres recherches et de consulter un conseiller financier qualifié avant toute décision d'investissement.
