u/BruhhhMomentummm

New Shai-Hulud npm worm variant
▲ 8 r/Malware+1 crossposts

New Shai-Hulud npm worm variant

There seems to be a new npm worm variant discovered today.

Steals GitHub tokens, uses GitHub's own commit search as P2P C2 (no private server), and leaves a dead-man's switch that triggers destructive actions if you revoke the token before removing persistence. The sigil in the commit message is: "IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner"

Full investigation of the variant and the IOC are in the link.

cybersecurityreach.org
u/BruhhhMomentummm — 11 days ago