View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Mini Shai-Hulud Worm Compromises Popular npm Codegen Package

๐Ÿšจ ACTIVE EXPLOITATION

  • Mini Shai-Hulud Worm Compromises Popular npm Codegen Package
    Attackers compromised the npm package @7nohe/openapi-react-query-codegen with a Mini Shai-Hulud worm.

    • The affected package is @7nohe/openapi-react-query-codegen, a TanStack Query code-generation library with more than 150,000 weekly downloads.
    • Malicious releases were 0.0.0-365d4eb738d3146583431948d3ba6e27a32556be, 0.0.0-ec7876d6c917dad516ba69bbfafc948b834bf0ab, 0.5.4, 0.5.5, 1.6.3, 1.6.4, 2.2.1, 2.2.2, 3.0.3, and 3.0.4.
    • An attacker abused a GitHub Actions workflow that allowed pull-request comments to trigger npm publishing from forked code, producing valid npm provenance.
    • Installation launched the obfuscated 3FWCvzduYZg.js loader through binding.gyp and, in later releases, a preinstall script.
    • The payload targeted GitHub, npm, PyPI, RubyGems, cloud, Kubernetes, Vault, SSH, and CI/CD credentials, then supported propagation through writable packages; related SHA-256 IOCs include b49afb7dba04cd99b357ce7c652c823a3707f28e130bd5c6645851a7adc030d6 and 59370c67b54a0ccaedd265e2356f04540b2fba1e1845300ef6de4d5437d99380.
      ๐Ÿ“„ Source: socket.dev ยท ๐Ÿ“Ž Coverage: gbhackers.com ยท ๐Ÿ‘ via Cyber Security News, cryptika.com (discovered)
  • Malicious Packagist Themes Target iPhones With Spyware and Wallet Theft
    Attackers used 13 malicious Composer themes to target iPhones with spyware and crypto-wallet theft.

    • Vietnamese movie and comic streaming sites using OphimCMS or KKPhim were affected, exposing their visitors.
    • Trojanized Packagist themes targeted iPhone XS through iPhone 16 devices running iOS 18.4โ€“18.6.x.
    • The packages exploited WebKit CVE-2025-31277 and CVE-2025-43529 through a browser-to-kernel attack chain.
    • Spyware stole keychain data, messages, photos, cookies, and wallet seeds from Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX.
    • Identified namespaces included vsmov, vsphim, haiau009, chilltvcms, and ophimcms; delivery infrastructure included union[.]macoms[.]la.
      ๐Ÿ“„ Source: socket.dev ยท ๐Ÿ“Ž Coverage: gbhackers.com ยท ๐Ÿ‘ via Cyber Security News, cryptika.com (discovered)
  • Five Venezuelan nationals plead guilty to attempted Kansas ATM jackpotting
    Five Venezuelan nationals pleaded guilty to attempted ATM jackpotting in Kansas.

    • Banks and credit unions operating ATMs in Wamego and Manhattan, Kansas, were targeted.
    • The suspects attempted to install malware that would force ATMs to dispense cash without authorized transactions.
    • One conspirator was to physically install the malware before the group remotely activated it.
    • The attempts failed, triggered alarms, and were captured on surveillance cameras.
      ๐Ÿ“„ Source: justice.gov ยท ๐Ÿ“Ž Coverage: therecord.media ยท ๐Ÿ‘ via BleepingComputer

๐Ÿ“‹ ADVISORIES

  • WatchGuard patches three critical Fireware OS VPN flaws
    WatchGuard patched three critical Fireware OS vulnerabilities enabling unauthenticated remote code execution.

    • WatchGuard Firebox customers using Fireware OS are affected.
    • The three flaws affect the Fireware iked process that handles IKE/IPsec VPN traffic.
    • Remote unauthenticated attackers can send crafted VPN traffic to trigger heap overflow, stack overflow, or type-confusion memory corruption.
    • Affected versions include Fireware 2025.0โ€“2026.2.1, 12.0โ€“12.12.1, and T15/T35 builds below 12.5.20; CVEs are CVE-2026-19313, CVE-2026-19315, and CVE-2026-19318.
      ๐Ÿ“„ Source: watchguard.com ยท ๐Ÿ“Ž Coverage: blog.gridinsoft.com ยท ๐Ÿ‘ via SecurityWeek
  • ๐Ÿ“„ Source for Attackers Exploit Critical Ruby on Rails KindaRails2Shell Flaw โ€” docs.vulncheck.com

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check