{"id":312512,"date":"2025-12-12T18:32:11","date_gmt":"2025-12-12T18:32:11","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/312512\/"},"modified":"2025-12-12T18:32:11","modified_gmt":"2025-12-12T18:32:11","slug":"microsoft-worm-attack-warning-act-rapidly-and-change-passwords-now","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/312512\/","title":{"rendered":"Microsoft Worm Attack Warning \u2014 Act Rapidly And Change Passwords Now"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2025\/12\/1765564331_337_0x0.jpg\" alt=\"Microsoft Corporation logo appears on the screen of a smartphone\" data-height=\"2460\" data-width=\"3690\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>Change your password now, Microsoft urges as Shai-Hulud worm attacks continue.<\/p>\n<p>NurPhoto via Getty Images<\/p>\n<p>Updated December 12 with further technical details regarding the Shai-Hulud 2.0 Dune Worm attacks, alongside original reporting of the Microsoft mitigation recommendations for rapid credentials rotation and replacement.<\/p>\n<p>In response to what the Microsoft Defender Security Research Team has called \u201cone of the most significant cloud-native ecosystem compromises observed recently,\u201d it has urged organizations to act rapidly and replace passwords. Here\u2019s what you need to know about the so-called Shai-Hulud 2.0 Dune Worm attacks.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-1\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/10\/microsoft-and-cisa-issue-critical-new-alert-windows-attacks-confirmed\/\" target=\"_blank\" aria-label=\"Microsoft And CISA Issue Critical New Alert, Windows Attacks Confirmed\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/10\/microsoft-and-cisa-issue-critical-new-alert-windows-attacks-confirmed\/\" rel=\"nofollow noopener\">ForbesMicrosoft And CISA Issue Critical New Alert, Windows Attacks ConfirmedBy Davey Winder<\/a>Microsoft Issues Critical Warning Following Shai-Hulud 2.0 Dune Worm Attacks<\/p>\n<p>On September 23, the Cybersecurity Infrastructure and Security Agency, which refers to itself as America\u2019s Cyber Defense Agency, issued an <a class=\"color-link\" href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/09\/23\/widespread-supply-chain-compromise-impacting-npm-ecosystem\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/09\/23\/widespread-supply-chain-compromise-impacting-npm-ecosystem\" aria-label=\"urgent alert\">urgent alert<\/a> regarding a self-replicating worm, known as Shai-Hulud, targeting Application Programming Interface keys for cloud services such as <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/01\/15\/new-amazon-ransomware-attack-recovery-impossible-without-payment\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/01\/15\/new-amazon-ransomware-attack-recovery-impossible-without-payment\/\" target=\"_self\" aria-label=\"Amazon Web Services\" rel=\"nofollow noopener\">Amazon Web Services<\/a>, Google Cloud Platform, and <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/05\/11\/microsoft-confirms-critical-1010-cloud-security-vulnerability\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/05\/11\/microsoft-confirms-critical-1010-cloud-security-vulnerability\/\" target=\"_self\" aria-label=\"Microsoft Azure\" rel=\"nofollow noopener\">Microsoft Azure<\/a>. Fast-forward to now, and the Microsoft Defender Security Research Team has published new guidance for \u201cdetecting, investigating, and defending against the supply chain attack,\u201d as Shai-Hulud 2.0 enters the cyber equation. <\/p>\n<p>\u201cThe Shai\u2011Hulud 2.0 campaign builds on earlier supply chain compromises,\u201d Microsoft said, \u201cbut introduces more automation, faster propagation, and a broader target set.\u201d This includes executing malicious code during the pre-install phase of the infected npm managed packages, which means that it happens before any security checks can be made. \u201c<a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/01\/information-stealing-machine-behind-theft-of-18-billion-credentials\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/01\/information-stealing-machine-behind-theft-of-18-billion-credentials\/\" target=\"_self\" aria-label=\"Stolen credentials\" rel=\"nofollow noopener\">Stolen credentials<\/a> are exfiltrated to public attacker-controlled repositories,\u201d the warning continued, \u201cwhich could lead to further compromise.\u201d<\/p>\n<p>This supply chain attack is, Adi Bleih, a security researcher for external risk management at Check Point, told me, unusually aggressive as a result. \u201cBy activating before installation completes and exfiltrating secrets into attacker-controlled GitHub repositories,\u201d Bleih said, \u201cthe operators gained rapid access to significant volumes of cloud and developer credentials.\u201d <\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-3\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/12\/lastpass-data-breach---insufficient-security-exposed-16-million-users\/\" target=\"_blank\" aria-label=\"LastPass Data Breach \u2014 Insufficient Security Exposed 1.6 Million Users\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/12\/lastpass-data-breach---insufficient-security-exposed-16-million-users\/\" rel=\"nofollow noopener\">ForbesLastPass Data Breach \u2014 Insufficient Security Exposed 1.6 Million UsersBy Davey Winder<\/a>ReversingLabs Dissects Dune Worm<\/p>\n<p>Tomislav Peri\u010din, chief software architect at ReversingLabs, has published an in-depth technical analysis of Sha1-Hulud: The Second Coming. \u201cThe same worm capabilities used in the first wave are also present in the malware of this second wave,\u201d Peri\u010din explained, \u201cin that, once a package is infected, it spawns attacks of its own by allowing the worm to propagate through other open source packages the author maintains.\u201d Peri\u010din confirmed that the ReversingLabs analysis has identified in excess of 27,000 new GitHub repositories created by the Dune Worm during these latest attacks, intended for storing exfiltrated data from compromised users.<\/p>\n<p>According to the RL analysis, Shai-Hulud 2.0 has four main stages:<\/p>\n<p>After compromising an account, the worm looks for other packages maintained by the same account and creates new package versions with a \u201cpostinstall script, adding a malicious bundle.js\u201d that is executed when users install the package itself.The worm\u2019s script looks for environment tokens using the popular open-source TruffleHog tool capable of detecting \u201cmore than 800 different types of secrets, to identify the victims\u2019 secrets.\u201dThese are then exfiltrated to the aforementioned GutHub repositories and double Base64-encoded.Finally, the  Shai-Hulud 2.0 worm will try to create public copies of the repositories, described as Shai-hulud Migration. \u201cThe intent appears to be both exposure of source code and secrets embedded in private repos,\u201d Peri\u010din said, \u201cpossibly for the purpose of harvesting and re-use by malicious actors.\u201d<\/p>\n<p>Ken Johnson, chief technology officer of DryRun Security, meanwhile, confirmed that Shai-Hulud 2.0 is the third attack to have been attributed to a threat group identified as S1ngularity. \u201cThis second version of the Shai-Hulud worm tells us the attackers are refining their techniques and improving upon their previous mistakes,\u201d Johnson advised. As such, it\u2019s a \u201cmassively dangerous and disruptive campaign.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-4\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/11\/spiderman-spiderman---does-whatever-a-hacker-can\/\" target=\"_blank\" aria-label=\"Beware Of Spiderman-As-A-Service Web Of Attacks\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/11\/spiderman-spiderman---does-whatever-a-hacker-can\/\" rel=\"nofollow noopener\">ForbesBeware Of Spiderman-As-A-Service Web Of AttacksBy Davey Winder<\/a>Microsoft Defender Security Research Team Recommendations<\/p>\n<p>The Microsoft Defender Security Research Team mitigation recommendations are unequivocal:<\/p>\n<p>Rapidly rotate and revoke exposed credentials.Review the Key Vault assets on the critical asset management page and investigate any relevant logs for unauthorized access.Isolate affected CI\/CD agents or workspaces.Prioritize high-risk attack paths to reduce further exposure.Remove unnecessary roles and permissions granted to identities assigned to CI\/CD pipelines; specifically review access to key vaults.<\/p>\n<p>Don\u2019t delay, absorb all the <a class=\"color-link\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/12\/09\/shai-hulud-2-0-guidance-for-detecting-investigating-and-defending-against-the-supply-chain-attack\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/12\/09\/shai-hulud-2-0-guidance-for-detecting-investigating-and-defending-against-the-supply-chain-attack\/\" aria-label=\"Microsoft advice\">Microsoft advice<\/a> and act rapidly as has been recommended. You know it makes sense.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-2\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/10\/this-nuke-microsoft-windows-11-ai-tool-has-gone-viral\/\" target=\"_blank\" aria-label=\"Remove AI From Microsoft Windows Tool Has Gone Viral\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/10\/this-nuke-microsoft-windows-11-ai-tool-has-gone-viral\/\" rel=\"nofollow noopener\">ForbesRemove AI From Microsoft Windows Tool Has Gone ViralBy Davey Winder<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"Change your password now, Microsoft urges as Shai-Hulud worm attacks continue. NurPhoto via Getty Images Updated December 12&hellip;\n","protected":false},"author":2,"featured_media":312513,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[124270,84,82567,124266,59,124268,124269,124271,94715,124265,56,54,55,124267],"class_list":["post-312512","post","type-post","status-publish","format-standard","has-post-thumbnail","category-business","tag-microsoft-cloud-hack","tag-business","tag-dune","tag-dune-worm","tag-gb","tag-microsoft-cloud","tag-microsoft-cloud-worm","tag-microsoft-password-warnin-g","tag-password","tag-shai-hulud","tag-uk","tag-united-kingdom","tag-unitedkingdom","tag-worm"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/312512","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=312512"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/312512\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/312513"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=312512"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=312512"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=312512"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}