The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Shai-Hulud malware worms Red Hat npm package versions downloaded 80K times a week

Security researchers on Monday found dozens of Red Hat npm package releases infected with the Mini Shai-Hulud worm that TeamPCP cybercriminals recently open-sourced. The new supply chain attack hit at least 32 npm package releases published under the Red Hat Cloud Services namespace, according to security researchers from Google-owned Wiz, who traced the malware to one Red Hat employee’s compromised GitHub account. They said the affected packages are downloaded around 80,000 times a week. “The compromised account pushed malicious orphan commits to two RedHatInsights repositories, bypassing code review,” the threat hunters said in a Monday blog. “This happened across two waves of activity.” Wiz considers this a “live threat,” and says its researchers are actively monitoring it for any new developments. Socket, meanwhile, counted 95 affected package versions as of 11:00:22 UTC. The supply-chain security shop continues to monitor the ongoing attack and update the artifacts list – so be sure to check it out, and if your organization or any development pipelines have installed one of the poisoned versions, assume compromise and immediately rotate credentials. The compromised versions execute a hidden payload through a preinstall hook so that the malware automatically runs during the npm install process – before a developer imports or uses the package. “Based on Socket’s analysis, the payload is designed to collect GitHub Actions secrets, npm tokens, cloud credentials, Kubernetes and Vault material, SSH keys, Git credentials, and other sensitive files,” Socket’s research team wrote on Monday. “It also includes encrypted exfiltration logic and GitHub-based fallback mechanisms, indicating that the attacker was not only attempting to steal credentials, but also potentially enable further supply chain propagation.” A Red Hat spokesperson told The Register that the IBM-owned software firm is aware of the reports. “We immediately initiated an investigation and removed the packages from the npm registry,” the spokesperson said. “The packages are strictly limited to internal development, and the malicious code was never published for customer consumption via the console.redhat.com system. While our investigation is ongoing, we have not identified any impact to customer or partner environments or Red Hat production systems.” Both security firms say the malware resembles the Mini Shai-Hulud worm – but because TeamPCP open sourced the credential-stealing tool, it’s tough to say whether TeamPCP or a copycat crew is responsible for the latest developer-targeting supply chain infection. According to Wiz, the modifications look “largely cosmetic, with references to the Dune universe replaced by Greek mythology themes (i.e ‘spartan’), while the underlying functionality and tradecraft remain substantially similar.” One of the notable changes, the security sleuths said, is that the new variant adds data collectors for Google Cloud Platform and Microsoft Azure identities, and this new capability snarfs up all the identities that the infected machine has access to, as opposed to just stealing secrets from the cloud environments. This suggests “an increased attacker focus on gaining and leveraging access to the cloud itself,” Wiz warns. This variant also creates repositories containing the description “Miasma: The Spreading Blight.” And unlike earlier variants of the self-spreading worm that copied themselves, this one generates a uniquely encrypted payload for each infection, which makes hash-based indicators-of-compromise useful only for a specific package version. ®

Slashdot

News for nerds, stuff that matters

Anthropic Invites EU To Access Mythos

An anonymous reader quotes a report from Politico: Anthropic has extended an invitation to the European Commission granting the EU's cyber agency access to its powerful AI hacking tool Mythos, according to a Commission official familiar with the process. The AI firm made the formal invitation after a meeting with the Commission in San Francisco last Thursday, the official said, adding the EU now has to put in place a mechanism to access the model with proper security safeguards.

European Commission spokesperson Thomas Regnier said in a statement the Commission has had "several productive meetings with Anthropic" and "welcome[d] the latest developments on potential future access." [...] "This latest development is of utmost importance to get a clear picture on the potential risks," Regnier said, adding: "Let's not forget that Mythos is not one off, a new wave of powerful models are coming to the market." An ENISA official said the agency does not have active access now but is working to implement it. The Commission is working on a formal action plan to respond to powerful AI hacking tools. It has indicated it wants to release it before the summer break, according to an industry official. Anthropic's Mythos was unveiled in early April and triggered fears that it could enable large-scale attacks with its ability to find and exploit vulnerabilities. "European authorities for weeks were shut off from accessing the cutting-edge cybersecurity AI tech, leading to urgent calls by European politicians and government officials to gain access," notes Politico. "Cyber officials also called for Europe to build its own version."

Read more of this story at Slashdot.

this isn't happiness.

ART, PHOTOGRAPHY, DESIGN & DISAPPOINTMENT INSTAGRAM ★ ELSEWHERES

I see green, icy blue - Giorgos Galanopoulos







I see green, icy blue - Giorgos Galanopoulos

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Mexico City police teargas teachers’ protest 10 days before World Cup

Clash began when teachers broke through metal barrier at entrance to Zocalo plaza, where fans will watch game

Mexico City police hurled teargas at protesting teachers to keep them from reaching the historic square where the “Fan fest” for the 2026 World Cup is under construction, according to AFP journalists.

The clash started when teachers broke through one of the metal barriers that have been set up at the entrance to the Zocalo plaza, a block from the government palace and a giant screen where fans will watch Mexico’s first World Cup game on 11 June.

Continue reading...

Sadiq Khan vows to overrule residents’ group’s objections to Soho bars and restaurants

London mayor says Soho Society’s decision to challenge all new licensing applications is ‘bad’ for city

Sadiq Khan, the London mayor, has suggested he will overrule a residents’ society that has vowed to challenge all new applications for pubs and restaurants in Soho.

The Guardian revealed last week that the Soho Society, a residents’ group established in 1972 aimed at “preserving the character of Soho”, voted for a new licensing mandate, meaning it will challenge all new applications for bars and restaurants in the area, including renewals of existing licences.

Continue reading...

VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

Denemarken krijgt na lang onderhandelen centrumlinks kabinet met Frederiksen als premier

Coalitie eindelijk een feit; Denemarken krijgt centrumlinks kabinet met Frederiksen als premier

Netanyahu dreigt Beiroet alsnog aan te vallen als Hezbollah geweld voortzet

Oranje-tegenstander Tunesië verliest oefenduel tegen tien man van Oostenrijk

kottke.org

Jason Kottke's weblog, home of fine hypertext products

Why Wildfire Experts Are So Worried About This Year’s...

Why Wildfire Experts Are So Worried About This Year’s Fire Season. “Key environmental indicators show that the nation is a tinderbox, gripped by widespread drought and with a light snowpack in the mountains.”