The record
Written from the 1 report below. Nothing here is unsourced.
- A worm called Shai-Hulud can now scan for stolen credentials in 469 different locations across developer tools, CI/CD systems, cloud configurations, and AI tool settings.
- Earlier versions of the worm scanned only 189 paths, so its search capability has more than doubled.
- Stolen credentials allow attackers to move from one compromised system to another, such as using a developer token to reach source code and then cloud infrastructure.
- Package publishing credentials are a priority risk because they let attackers distribute malicious software through channels developers already trust.
- The report urges organizations to replace long-lived publishing tokens with short-lived, verified authentication such as OpenID Connect, and to prioritize remediation based on which credentials attackers would target first.
Coverage1
1 report
English national1
All filed from India
Named India · AWS · Docker · GitHub · Kubernetes · GitGuardian · Shai-Hulud
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
