

Risky Business #807 -- Shai-Hulud npm worm wreaks old-school havoc
38 snips Sep 17, 2025
In this discussion, Adam Pointon, CEO and co-founder of Knock Knock, shares insights on innovative identity authentication solutions and their application in securing internal services. The conversation dives into the alarming Shai-Hulud npm worm, which can steal developer credentials, and the significant ransomware attack on Jaguar Land Rover that threatens smaller suppliers. They also tackle concerns surrounding vulnerabilities in popular cybersecurity systems like Kerberos and discuss practical strategies for navigating the complexities of network security.
AI Snips
Chapters
Books
Transcript
Episode notes
NPM Worm Revives Internet-Scale Self-Replication
- A self-replicating worm hit npm, stealing credentials and injecting itself into maintainer packages to propagate.
- The worm published stolen secrets to public GitHub repos, amplifying damage and exposure.
Revoke Compromised Publish Tokens Fast
- Monitor package publish tokens and rotate credentials used for repository automation immediately after compromise.
- Revoke affected npm tokens and audit recent package publishes to prevent automated repackaging and re-release.
Ransomware vs Data Extortion Differ In Impact
- Ransomware causing production shutdowns creates systemic supplier risk and possible bankruptcies across industries.
- Data extortion is growing and often causes less operational disruption than destructive ransomware.