216.73.217.22

Defending Against Sha1-Hulud: The Second Coming

· Published 27/11/2025 14:13 · Modified 21/12/2025 18:08

Export JSON

Essential information

Published
27/11/2025 14:13
Modified
21/12/2025 18:08
Tags
2025-11-27 cloud credentials github actions npm package compromise persistence sha1-hulud software development supply chain attack
Related entities
3 observables, 17 techniques (mitre), 1 malware

Description

A new variant of the , dubbed , has emerged with enhanced capabilities. Unlike its predecessor, this attack executes in the preinstall phase, targeting popular packages such as Postman, Zapier, and AsyncAPI. The malware harvests credentials across AWS, Azure, and GCP, and establishes through . It creates a self-hosted runner named 'SHA1HULUD' and adds a workflow with an injection vulnerability. The attack's impact extends beyond the development environment, potentially allowing lateral movement across cloud infrastructures. Immediate actions recommended include removing compromised packages, revoking and regenerating tokens and credentials, and enforcing hardware-based MFA for developer accounts.

External references