{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Threat Talks - Your Gateway to Cybersecurity Insights","title":"The Npm Worm Outbreak","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/8bbd2a4d\"></iframe>","width":"100%","height":180,"duration":1107,"description":"The world’s biggest open-source ecosystem - npm - faced its first self-spreading worm.\n\nThey called it Shai Hulud.\n\nIt didn’t just infect one package. It infected developers themselves.\n\nWhen a maintainer got phished, the worm harvested credentials, hijacked tokens, and created new CI/CD workflows to keep spreading - automatically.\n\nNo command-and-control. No manual uploads. Just a chain reaction across the npm registry.\n\nAnd while the world was busy shouting about “2.6 billion downloads affected,” this real threat was quietly exfiltrating GitHub, cloud, and npm secrets - right under everyone’s nose.\n\nThis isn’t just another npm story.\n\nIt’s the first-ever self-replicating supply chain worm - and a wake-up call for every developer and security team building in the open.\n\nWatch host Rob Maas (Field CTO, ON2IT) and Yuri Wit (SOC Analyst, ON2IT) \nbreak down how it started, how it spread, and how to make sure your pipeline isn’t the next one to go viral.\n\nKey Topics Covered\nHow a maintainer phish and TOTP capture led to a crypto drainer in npm.\nWhy Shai Hulud’s credential harvesting + CI/CD persistence makes it high-impact.\nPractical defenses: pin/review dependencies, CI/CD change alerts, secret rotation, egress monitoring.\nWhat developers vs. end users can (and can’t) do in supply-chain attacks.\nGot your attention? \nSubscribe to Threat Talks and turn on notifications for more content on the world’s leading cyber threats and trends.\n\nGuest and Host Links: \nRob Maas (Field CTO, ON2IT): https://www.linkedin.com/in/robmaas83/  \nYuri Wit (SOC Analyst, ON2IT): https://www.linkedin.com/in/yuriwit/  \n \nAdditional Resources\n Threat Talks: https://threat-talks.com/\nON2IT (Zero Trust as a Service): https://on2it.net/\nAMS-IX: https://www.ams-ix.net/ams\nnpm: https://www.npmjs.com/\nNode.js: https://nodejs.org/\nGitHub Docs: Actions & Workflows: https://docs.github.com/actions\nMetaMask: https://metamask.io/\nOWASP Dependency Management:...","thumbnail_url":"https://img.transistorcdn.com/zxiRQtIn39fLuEqIC458HdYTjdufBy-QMdJtCYFz97Y/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8xN2Q1/NGE1NjBhYWY0ZmY5/NzEyODA5OGU3NDdi/MmNmYi5qcGc.webp","thumbnail_width":300,"thumbnail_height":300}