{"id":158012,"date":"2025-09-20T23:26:08","date_gmt":"2025-09-20T23:26:08","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/158012\/"},"modified":"2025-09-20T23:26:08","modified_gmt":"2025-09-20T23:26:08","slug":"a-dangerous-worm-is-eating-its-way-through-software-packages","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/158012\/","title":{"rendered":"A Dangerous Worm Is Eating Its Way Through Software Packages"},"content":{"rendered":"<p>New findings this week showed that <a href=\"https:\/\/www.wired.com\/story\/a-dhs-data-hub-exposed-sensitive-intel-to-thousands-of-unauthorized-users\/\" rel=\"nofollow noopener\" target=\"_blank\">a misconfigured platform used by the Department of Homeland Security<\/a> left sensitive national security information\u2014including data related to the surveillance of Americans\u2014exposed and accessible to thousands of people. Meanwhile, 15 New York officials <a href=\"https:\/\/www.wired.com\/story\/ice-mass-arrests-new-york-officials\/\" rel=\"nofollow noopener\" target=\"_blank\">were arrested by Immigration and Customs Enforcement and the New York Police Department this week in or around 26 Federal Plaza<\/a>\u2014where ICE detains people in what courts have ruled are unsanitary conditions.<\/p>\n<p class=\"paywall\">Russia conducted conspicuous <a href=\"https:\/\/www.wired.com\/story\/russia-hypersonic-missile-test-nato-borders\/\" rel=\"nofollow noopener\" target=\"_blank\">military exercises testing hypersonic missiles<\/a> near NATO borders, stoking tensions in the region after the Kremlin had already recently flown drones into Polish and Romanian airspace. Scammers have a <a href=\"https:\/\/www.wired.com\/story\/sms-blasters-scam-texts\/\" rel=\"nofollow noopener\" target=\"_blank\">new tool for sending spam texts, known as \u201cSMS blasters<\/a>,\u201d that can send up to 100,000 texts per hour while evading telecom company anti-spam measures. Scammers deploy rogues cell towers that trick people&#8217;s phones into connecting to the malicious devices so they can send the texts directly and bypass filters. And a pair of flaws in Microsoft&#8217;s Entra ID identity and access management system, which have been patched, <a href=\"https:\/\/www.wired.com\/story\/microsoft-entra-id-vulnerability-digital-catastrophe\/\" rel=\"nofollow noopener\" target=\"_blank\">could have been exploited to access virtually all Azure customer accounts<\/a>\u2014a potentially catastrophic disaster.<\/p>\n<p class=\"paywall\">WIRED published a <a href=\"https:\/\/www.wired.com\/story\/how-to-set-up-use-burner-phone\/\" rel=\"nofollow noopener\" target=\"_blank\">detailed guide this week to acquiring and using a burner phone<\/a>, as well as alternatives that are more private than a regular phone but not as labor-intensive as a true burner. And we updated our <a href=\"https:\/\/www.wired.com\/gallery\/best-vpn\/\" rel=\"nofollow noopener\" target=\"_blank\">guide to the best VPNs<\/a><\/p>\n<p class=\"paywall\">But wait, there\u2019s more! Each week, we round up the security and privacy news we didn\u2019t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there.<\/p>\n<p class=\"paywall\">The cybersecurity world has seen, to its growing dismay, plenty of <a href=\"https:\/\/www.wired.com\/story\/hacker-lexicon-what-is-a-supply-chain-attack\/\" rel=\"nofollow noopener\" target=\"_blank\">software supply chain attacks<\/a>, in which hackers hide their code in a legitimate piece of software so that it\u2019s silently seeded out to every system that uses that code around the world. In recent years, hackers have even tried linking <a href=\"https:\/\/www.wired.com\/story\/3cx-supply-chain-attack-times-two\/\" rel=\"nofollow noopener\" target=\"_blank\">one software supply chain attack to another<\/a>, finding a second software developer target among their victims to compromise yet another piece of software and launch a new round of infections. This week saw a new and troubling evolution of those tactics: A full-blown self-replicating supply chain attack worm.<\/p>\n<p class=\"paywall\">The malware, which has been dubbed Shai-Hulud after the Fremen name for the monstrous Sandworms in the sci-fi novel Dune (and the name of the Github page where the malware published stolen credentials of its victims) has compromised hundreds of open-source software packages on the code repository Node Packet Management, or NPM, used by developers of Javascript. The Shai-Hulud worm is designed to infect a system that uses one of those software packages, then hunt for more NPM credentials on that system so that it can corrupt another software package and continue its spread.<\/p>\n<p class=\"paywall\">By one count, the worm has spread to <a data-offer-url=\"https:\/\/krebsonsecurity.com\/2025\/09\/self-replicating-worm-hits-180-software-packages\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/krebsonsecurity.com\/2025\/09\/self-replicating-worm-hits-180-software-packages\/&quot;}\" href=\"https:\/\/krebsonsecurity.com\/2025\/09\/self-replicating-worm-hits-180-software-packages\/\" rel=\"nofollow noopener\" target=\"_blank\">more than 180 software packages<\/a>, including 25 used by the cybersecurity firm CrowdStrike, though CrowdStrike has since had them removed from the NPM repository. Another count from cybersecurity firm ReversingLabs put the count far higher, at <a data-offer-url=\"https:\/\/www.darkreading.com\/application-security\/self-replicating-shai-hulud-worm-npm-packages\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.darkreading.com\/application-security\/self-replicating-shai-hulud-worm-npm-packages&quot;}\" href=\"https:\/\/www.darkreading.com\/application-security\/self-replicating-shai-hulud-worm-npm-packages\" rel=\"nofollow noopener\" target=\"_blank\">more than 700 affected code packages<\/a>. That makes Shai-Hulud one of the biggest supply chain attacks in history, though the intent of its mass credential-stealing remains far from clear.<\/p>\n<p class=\"paywall\">Western privacy advocates have long pointed to China\u2019s surveillance systems as the potential dystopia awaiting countries like the United States if tech industry and government data collection goes unchecked. But a sprawling Associated Press investigation highlights how China\u2019s surveillance systems have reportedly been largely built on US technologies. The AP\u2019s reporters found evidence that China\u2019s surveillance network\u2014from the \u201cGolden Shield\u201d policing system that Beijing officials have used to censor the internet and crack down on alleged terrorists to the tools used to target, track and often detain Uyghurs and the country\u2019s Xinjiang region\u2014appear to have been built with the help of American companies, including IBM, Dell, Cisco, Intel, Nvidia, Oracle, Microsoft, Thermo Fisher, Motorola, Amazon Web Services, Western Digital, and HP. In many cases, the AP found Chinese-language marketing materials in which the Western companies specifically offering surveillance applications and tools to Chinese police and domestic intelligence services.<\/p>\n<p class=\"paywall\">Scattered Spider, a rare hacking and extortion cybercriminal gang based largely in Western countries, has for years unleashed a trail of chaos across the internet, hitting targets from MGM Resorts and Caesar\u2019s Palace to the Marks &amp; Spencer grocery chain in the United Kingdom. Now two alleged members of that notorious group have been arrested in the UK: 19-year-old Thalha Jubair and 18-year-old Owen Flowers, both charged with hacking the Transport for London transit system\u2014reportedly inflicting more than $50 million in damage\u2014among many other targets. Jubair alone is accused of intrusions targeting 47 organizations. The arrests are just the latest in a string of busts targeting Scattered Spider, which has nonetheless continued a nearly uninterrupted string of breaches. Noah Urban, who was convicted on charges related to Scattered Spider activity, spoke from jail to Bloomberg Businessweek for a <a data-offer-url=\"https:\/\/www.bloomberg.com\/news\/features\/2025-09-19\/multimillion-dollar-hacking-spree-scattered-spider-teen-s-jailhouse-confessions?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTc1ODI4MTkwMSwiZXhwIjoxNzU4ODg2NzAxLCJhcnRpY2xlSWQiOiJUMlUyTVNHUTFZWVUwMCIsImJjb25uZWN0SWQiOiIwNUVDNUJDRTNFOTA0ODQ0OThBOTc5MkM0MDIwNkUzNyJ9.hZarEq-EdSn6zXTfZnJEI870hLN66BhFQhLN7kqmKds&amp;leadSource=uverify%20wall\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.bloomberg.com\/news\/features\/2025-09-19\/multimillion-dollar-hacking-spree-scattered-spider-teen-s-jailhouse-confessions?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTc1ODI4MTkwMSwiZXhwIjoxNzU4ODg2NzAxLCJhcnRpY2xlSWQiOiJUMlUyTVNHUTFZWVUwMCIsImJjb25uZWN0SWQiOiIwNUVDNUJDRTNFOTA0ODQ0OThBOTc5MkM0MDIwNkUzNyJ9.hZarEq-EdSn6zXTfZnJEI870hLN66BhFQhLN7kqmKds&amp;leadSource=uverify%20wall&quot;}\" href=\"https:\/\/www.bloomberg.com\/news\/features\/2025-09-19\/multimillion-dollar-hacking-spree-scattered-spider-teen-s-jailhouse-confessions?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTc1ODI4MTkwMSwiZXhwIjoxNzU4ODg2NzAxLCJhcnRpY2xlSWQiOiJUMlUyTVNHUTFZWVUwMCIsImJjb25uZWN0SWQiOiIwNUVDNUJDRTNFOTA0ODQ0OThBOTc5MkM0MDIwNkUzNyJ9.hZarEq-EdSn6zXTfZnJEI870hLN66BhFQhLN7kqmKds&amp;leadSource=uverify%20wall\" rel=\"nofollow noopener\" target=\"_blank\">long profile of his cybercriminal career<\/a>. Urban, 21, has been sentenced to a decade in prison.<\/p>\n","protected":false},"excerpt":{"rendered":"New findings this week showed that a misconfigured platform used by the Department of Homeland Security left sensitive&hellip;\n","protected":false},"author":2,"featured_media":158013,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[49,48,283,8907,7474,5545,2532,82640,48798,61],"class_list":["post-158012","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-ca","tag-canada","tag-cybersecurity","tag-hacking","tag-malware","tag-privacy","tag-security","tag-security-roundup","tag-surveillance","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/158012","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=158012"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/158012\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/158013"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=158012"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=158012"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=158012"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}