HomeTechnologyIndian government issue serious security warning for these Google, Amazon and Microsoft services: All the detaisl

Indian government issue serious security warning for these Google, Amazon and Microsoft services: All the detaisl

CERT-In has issued a high-severity warning over a major npm ecosystem compromise named ‘Shai-Hulud,’ targeting credentials linked to Google Cloud, AWS, Microsoft Azure, and developer accounts.

October 08, 2025 / 21:36 IST
Story continues below Advertisement
Cert-In
Cert-In

The Indian Computer Emergency Response Team (CERT-In) has issued a high-severity advisory warning developers and organizations about an ongoing software supply chain attack targeting the Node Package Manager (npm) ecosystem. The attack, driven by a self-replicating worm called Shai-Hulud, has already compromised over 500 npm packages, posing a significant threat to companies using JavaScript and Node.js frameworks across sectors such as IT, fintech, startups, and e-Governance platforms.⸻

Nature of the attack

Story continues below Advertisement

According to the advisory (CIAD-2025-0034) issued on September 25, 2025, the Shai-Hulud campaign leverages phishing emails impersonating npm to steal developer credentials under the guise of “MFA update” prompts. Once credentials are compromised, attackers deploy malware designed to harvest authentication tokens and cloud service keys. The malicious code is embedded in npm packages through the post-installation (“postinstall”) script, enabling automatic credential theft and further spread of infected code.

The malware primarily targets sensitive credentials such as npm tokens, GitHub Personal Access Tokens (PATs), and API keys associated with Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure. These credentials are exfiltrated to an attacker-controlled endpoint and uploaded to a public repository named Shai-Hulud on GitHub, from where the infection proliferates to other packages automatically.