[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fbDEiffQuCWoa5WNbpuGnNuu-EkFypDdiVJIM6xk2AXQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"55443a86-0dd5-4b20-8743-386bd91f8787","shai-hulud-worm-marks-one-year-of-npm-supply-chain-damage","3994502a-5152-4438-936d-17f45906ba17","Shai-Hulud Worm Marks One Year of npm Supply Chain Damage","The Shai-Hulud worm demonstrates how a single compromised open-source package can serve as a persistent beachhead for ongoing, evolving supply chain attacks. By harvesting credentials and leveraging OIDC tokens, the worm expanded its reach far beyond the initial @ctrl\u002Ftinycolor compromise, illustrating that supply chain threats are not one-time events but long-lived campaigns. The open-sourcing of the worm framework by TeamPCP amplified the threat by lowering the barrier for other attackers to adopt and adapt the tooling. This incident underscores that organizations must treat third-party package dependencies as a critical attack surface requiring continuous scrutiny, not just point-in-time review.","**Immediate actions:**\n- Audit all npm (and other package registry) dependencies for known-compromised packages, starting with @ctrl\u002Ftinycolor and its dependents.\n- Rotate all credentials and OIDC tokens that may have been exposed via affected packages or CI\u002FCD pipelines.\n- Enable software composition analysis (SCA) tooling in all build pipelines to flag newly flagged malicious packages automatically.\n\n**Long-term improvements:**\n- Maintain a Software Bill of Materials (SBOM) for every application and review it whenever upstream packages publish new versions.\n- Implement dependency pinning and integrity verification (e.g., lockfiles and hash checks) to prevent silent package substitution.\n- Establish a vendor\u002Fopen-source risk management program that scores and monitors the health and trustworthiness of critical dependencies.\n\n**Detection measures:**\n- Monitor CI\u002FCD pipeline logs and runtime environments for unexpected outbound credential transmission or token usage anomalies.\n- Subscribe to security advisories from npm, OSV, and relevant CERTs to receive early warning of newly identified malicious packages.\n- Deploy runtime application self-protection (RASP) or eBPF-based monitoring to detect self-propagation behaviors indicative of worm activity.",[12,13,14,15,16,17,18,19,20],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management Practices","NIST SP 800-218 (SSDF): Secure Software Development Framework","NIST CSF ID.SC-4: Suppliers are routinely assessed","NIST AC-6: Least Privilege (limiting OIDC token scope)","SLSA Supply Chain Levels for Software Artifacts (Levels 2–4)","GDPR Article 32: Security of Processing (credential exposure implications)","OpenSSF Scorecard for open-source dependency evaluation","published","2026-09-18T22:20:39.663253+00:00","2026-09-18T22:20:39.543+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fhappy-birthday-shai-hulud?utm_medium=feed","happy-birthday-shai-hulud-58c7a2","Happy Birthday, Shai-Hulud",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[48,54],{"id":49,"date":50,"edition":51,"title":52,"audio_url":53},"e4ddf157-8a72-499f-ab71-e2da6f4258e8","2026-09-20","afternoon","ThreatNoir Weekend Brief — September 20","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-09-20\u002Fthreatnoir-afternoon-brief-2026-09-20.mp3",{"id":55,"date":56,"edition":57,"title":58,"audio_url":59},"720d8f46-1f79-4b3b-8389-af7d6c8e8bef","2026-09-19","morning","ThreatNoir Weekend Brief — September 19","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-09-19\u002Fthreatnoir-morning-brief-2026-09-19.mp3"]