{"id":788,"date":"2025-09-23T08:00:53","date_gmt":"2025-09-23T06:00:53","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=788"},"modified":"2025-09-24T08:01:30","modified_gmt":"2025-09-24T06:01:30","slug":"widespread-supply-chain-compromise-impacting-npm-ecosystem","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2025\/09\/23\/widespread-supply-chain-compromise-impacting-npm-ecosystem\/","title":{"rendered":"Widespread Supply Chain Compromise Impacting npm Ecosystem"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">CISA is releasing this Alert to provide guidance in response to a widespread software supply chain compromise involving the world\u2019s largest JavaScript registry, npmjs.com. A self-replicating worm\u2014publicly known as \u201cShai-Hulud\u201d\u2014has compromised over 500 packages.<a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/09\/23\/widespread-supply-chain-compromise-impacting-npm-ecosystem#_edn1\">[i]<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After gaining initial access, the malicious cyber actor deployed malware that scanned the environment for sensitive credentials. The cyber actor then targeted GitHub Personal Access Tokens (PATs) and application programming interface (API) keys for cloud services, including Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure.<\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2025\/09\/23\/widespread-supply-chain-compromise-impacting-npm-ecosystem\/\" target=\"_self\"><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/09\/23\/widespread-supply-chain-compromise-impacting-npm-ecosystem\">Widespread Supply Chain Compromise Impacting npm Ecosystem | CISA<\/a><span class=\"screen-reader-text\">: Widespread Supply Chain Compromise Impacting npm Ecosystem<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>CISA is releasing this Alert to provide guidance in response to a widespread software supply chain compromise involving the world\u2019s largest JavaScript registry, npmjs.com. A self-replicating worm\u2014publicly known as \u201cShai-Hulud\u201d\u2014has compromised over 500 packages.[i] After gaining initial access, the malicious cyber actor deployed malware that scanned the environment for sensitive&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12],"tags":[40],"class_list":["post-788","post","type-post","status-publish","format-standard","hentry","category-supply-chain-attack","tag-40"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/788","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=788"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/788\/revisions"}],"predecessor-version":[{"id":789,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/788\/revisions\/789"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=788"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=788"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=788"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}