Retrospective: How Malicious Software Updates Poison Development Environments

· Original article ↗

Summary

A retrospective examines S1ngularity, Shai-Hulud and TeamPCP supply-chain attacks, detailing how stolen credentials and malicious package updates spread malware, steal secrets and compromise downstream projects.

Key points

  • Attackers compromise supplier credentials or CI/CD pipelines to publish malicious updates to trusted open-source packages, which can automatically reach downstream users.
  • S1ngularity used malicious Nx package updates to search for credentials, tokens and SSH keys, including by prompting victims’ local AI agents, then exfiltrated secrets through public GitHub repositories.
  • Shai-Hulud stole npm publishing tokens and republished itself as a worm, spreading without requiring a software vulnerability; later variants included Mini Shai-Hulud.
  • TeamPCP used credentials from the Trivy compromise in further supply-chain attacks, including compromises involving Checkmarx, LiteLLM, Telnyx and more than 60 npm packages.
  • The article says Nx moved to GitHub Trusted Publisher to replace long-lived tokens with short-lived, per-run credentials; it also stresses credential rotation and CI/CD security.
  • The article attributes suspected damages of hundreds of millions of dollars to TeamPCP and reports that two people in Australia were arrested in connection with the group.

Article Details

Attack Vectors
  • Attackers compromised publishing credentials or CI/CD access, then released malicious updates to popular open-source packages.
  • In the S1ngularity attack, a crafted pull request helped attackers obtain a token, replace an Nx CI script, steal an npm publishing token, and publish infected packages.
  • Malicious Nx post-install hooks searched for credentials and SSH keys, prompted local AI agents to find additional files, and exposed stolen information through public GitHub repositories.
  • Shai-Hulud and CanisterWorm searched infected systems for npm publishing tokens and used them to publish malicious updates to additional packages.
  • TeamPCP used a compromised service account to modify Trivy version tags relied on by running CI/CD workflows and distribute a malicious update.
  • ChainDrop used a Mini Shai-Hulud variant with an obfuscated Bun JavaScript payload.
Defensive Notes
  • Nx moved to GitHub's Trusted Publisher model to replace long-lived publishing tokens with short-lived, per-run credentials.
  • The Trivy incident illustrates the risk of incomplete credential rotation after a known compromise.
  • Review repository and CI/CD pipeline misconfigurations, publishing-token permissions, and the trust placed in automated dependency updates.

Indicators of compromise

TypeIndicatorContext
SHA12379ac0e03b1a67c4ca5693136eff4945e644a91Sample identified with a revised S1ngularity file-search prompt.
SHA1b4f20b39aa6df1002872f07973024d85aa49abafSample identified with a S1ngularity prompt used to seek files containing credentials.
SHA1d2438106211ebd12c4f0a248848bc9864c97a3c0Sample identified in the article's analysis of malicious S1ngularity code and prompts.
SHA1e5d1f3c45ee7cca6ae59cf64e0573050bbe136ecSample identified with the final S1ngularity file-search prompt described in the article.

MITRE ATT&CK

Threat Actors

Malware

Vendors

Products

BunBoth of these attacks had a more sophisticated version of Shai-Hulud. The second wave leveraged bun to execute the file with the malicious code. The worm traveled far and infected many systems.  TeamPCP, which will beGitHubS1ngularity turned AI agents against their own users. The malicious Nx update prompted victims' local AI tools to hunt for GitHub, npm, cloud and SSH credentials. It was the first notable attack to use this tactic.LiteLLMnext attack. An incomplete credential rotation after the Trivy breach led to compromises of Checkmarx, LiteLLM, Telnyx and more than 60 npm packages. The damages reached hundreds of millions of dollars.npmS1ngularity turned AI agents against their own users. The malicious Nx update prompted victims' local AI tools to hunt for GitHub, npm, cloud and SSH credentials. It was the first notable attack to use this tactic.NxS1ngularity turned AI agents against their own users. The malicious Nx update prompted victims' local AI tools to hunt for GitHub, npm, cloud and SSH credentials. It was the first notable attack to use this tactic.OpenVSXattack started with a Pwn Request to exfiltrate a CI token, then deployed the worm through a malicious OpenVSX extension. The other attack targeted projects like Zapier, PostHog, and Postman by exploiting long-livedPyPIonto the dark web. Another victim was LiteLLM, where attackers uploaded a malicious package directly to PyPi. Telnyx had a similar compromise as LiteLLM, with publication through PyPi. TrivyTeamPCP used each stolen credential to launch the next attack. An incomplete credential rotation after the Trivy breach led to compromises of Checkmarx, LiteLLM, Telnyx and more than 60 npm packages. The damages reachedTrusted PublisherIn response to this attack, Nx’s moved to GitHubs Trusted Publisher model. This model seeks to stop the usage of long lasting tokens, replacing them with something short-lived and per-run. It helps eliminate token theft

Industries

Related Articles