Sha1-Hulud has a dead man's switch
Uncategorized
1
Posts
1
Posters
0
Views
-
Sha1-Hulud has a dead man's switch
The second iteration of the Shai-Hulud worm had a dead man's switch that destroys data on infected machines.
If it can't reach Github or npm to self-propagate, the worm spawns a cmd.exe / bash shell and tries to delete all data that can be written by the current user. Yikes.It seems sha1-hulud is now contained though: Only about 300 infected repos are left.
https://about.gitlab.com/blog/gitlab-discovers-widespread-npm-supply-chain-attack/
-
undefined oblomov@sociale.network shared this topic on