Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised
Key point
An npm package supply chain attack has been discovered that risks hijacking AI coding tools such as Claude Code and Codex.
Details
The npm account atool was compromised, and 637 malicious versions were mass-distributed across 317 packages within 22 minutes. The affected scope includes packages with large user bases, such as size-sensor (4.2 million downloads/month) and echarts-for-react (3.8 million downloads/month).
The core of this attack is targeting AI coding tools. The attacker injected a SessionStart hook into Claude Code and Codex, designing it so that malicious code re-executes every time an AI session starts. Additionally, it manipulates VS Code's tasks.json to trigger malicious code execution whenever a folder is opened.
The attacker steals a wide range of information, including:
- Cloud and infrastructure: AWS (EC2, ECS, Secrets Manager), Kubernetes, GCP, Azure credentials
- Development tools: GitHub PAT, npm tokens, SSH keys, Docker credentials
- Local security: Local password manager data such as 1Password, Bitwarden
The stolen data is either committed as Git objects to public GitHub repositories, or disguised as OpenTelemetry trace data and exfiltrated to an external server (t.m-kosche[.]com) via encrypted HTTPS POST requests.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.