GitHub and Grafana security incidents are likely related to the large-scale "Mini Sandworm" supply chain attack.

robot
Abstract generation in progress
ME News, May 20 (UTC+8), according to threat intelligence released by SlowMist, several high-frequency npm packages including AntV and Echarts-for-react, as well as the Python SDK durabletask, have recently been attacked by the Mini Shai-Hulud "Mini Sandworm" supply chain attack. The npm account atool was compromised, and the attacker automatically published 637 malicious versions across 317 packages within 22 minutes. The attacker continuously uploaded versions 1.4.1, 1.4.2, and 1.4.3 of durabletask within 35 minutes, bypassing normal release controls and impersonating Microsoft official releases. The large-scale GitHub token leak incident and the ransomware attack on Grafana Labs are likely related to this supply chain attack. Affected components include high-frequency components in the npm ecosystem such as AntV and Echarts-for-react, as well as Python package durabletask versions 1.4.1, 1.4.2, and 1.4.3. Attackers can steal cloud and local credentials, gain unauthorized access to internal repositories and sensitive cloud infrastructure, move laterally to developer machines and CI/CD pipelines, sell and exploit leaked GitHub tokens, and carry out ransomware and data breach threats. SlowMist recommends immediately rotating all exposed credentials, replacing affected packages, isolating potentially compromised systems, and implementing strict dependency review policies. Previously, the "Mini Sandworm" worm had achieved widespread infection in open source code repositories, and developers need to be vigilant in checking. (Source: ChainCatcher)
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned