Cyber Security News

Hackers Are Turning Trusted Software Updates Into Credential-Stealing Malware

A growing wave of supply-chain attacks is proving the opposite: attackers are compromising legitimate open-source packages and using trusted update channels to deploy credential-stealing malware directly into developer and enterprise environments.

Malicious Nx releases, published after attackers stole an npm publishing token through a GitHub Actions workflow flaw, ran post-install scripts that searched systems for sensitive data and uploaded it to attacker-controlled public GitHub repositories.

The compromised packages were available for roughly four hours, yet that was enough time to reach a significant number of developers.

What distinguished S1ngularity was its abuse of locally installed AI coding assistants.

The malware attempted to invoke tools such as Claude and Gemini and prompt them to locate GitHub credentials, npm tokens, cloud keys, SSH material and environment files.

In effect, attackers did not need to deploy a sophisticated custom discovery framework; they repurposed the victim’s own AI tooling to identify high-value secrets.

Nx described the incident as involving malicious packages that scanned devices, attempted to use local AI tools, and exfiltrated the findings through GitHub.

That tactic marked a major evolution in supply-chain compromise. The threat was not simply malicious code hidden in a dependency. It was malware that used trusted automation already present on the endpoint to accelerate credential discovery.

Shai-Hulud demonstrated the next stage: self-propagation. Rather than relying on a newly discovered software vulnerability, the worm stole npm publishing credentials from infected maintainers.

It used those credentials to publish malicious versions of additional packages. Every stolen token could therefore become the starting point for another compromise.

S1ngularity sample code showing the usage of “s1ngularity-repository” (Source : Reversinglabs).

Reversinglabs identified that, the trend became impossible to ignore after the S1ngularity incident, which weaponized compromised Nx packages to turn victims’ local AI tools into automated reconnaissance assistants.

Credential-Stealing Malware

The model is especially dangerous because it exploits the trust relationship at the center of modern software delivery.

Developers routinely install dependencies, CI/CD systems automatically resolve package updates, and organizations often allow build tooling wide access to source repositories, registries and cloud services.

A compromised update can therefore arrive through a channel that security controls and users already regard as legitimate.

Screenshot of prompt that was initially used by S1ngularity to get AI agents to seek out files that may contain credentials (Source : Reversinglabs).

The attack family has continued to evolve. In August, the ChainDrop campaign infected more than 400 npm packages with a Mini Shai-Hulud variant delivered through a heavily obfuscated Bun-based JavaScript payload, according to Microsoft Threat Intelligence.

Elastic Security Labs reported that the worm harvested credentials by matching more than 300 patterns across developer credential stores, with notable targeting of AI-development tooling including Anthropic, Claude, Codex, Cursor, OpenAI and Gemini.

The risk increased further when TeamPCP allegedly released Mini Shai-Hulud publicly and encouraged other actors to use it.

Once a functional credential-stealing worm is available as a reusable framework, attackers no longer need the capability to engineer propagation, package discovery and token abuse from scratch. They can focus on access, targeting and evasion.

That democratization helps explain why supply-chain attacks are increasingly chained together.

A token compromised in one incident can be used to poison another package, steal another set of credentials and expand the blast radius again. The attack path is no longer linear; it is recursive.

Authorities allege TeamPCP’s operations potentially compromised more than 1,000 organizations worldwide, exposed over 500,000 credentials and authentication materials, and resulted in the theft of at least 300 GB of data.

Two Western Australian men were charged following a joint Australian Federal Police, Western Australia Police Force and FBI investigation.

The central lesson is that package publishing credentials must be treated as production-critical identities.

Long-lived npm tokens, overly permissive GitHub Actions workflows and unmanaged CI/CD secrets give attackers a direct route into trusted software distribution.

Organizations should shift package publishing to short-lived, workload-bound credentials through trusted publishing and OIDC; enforce least privilege on repository and registry tokens.

Require review and provenance checks for dependency updates; continuously monitor for unexpected preinstall and postinstall behavior; and rotate credentials completely after any compromise.

The S1ngularity, Shai-Hulud and ChainDrop campaigns show that a compromised software update is no longer merely a malware-delivery event.

It can become a credential-harvesting operation, a cloud-access incident and a launchpad for the next supply-chain attack all before defenders realize a trusted dependency has turned hostile.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Mayura Kathir

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago