HNHacker News
TopNewBestAskShowJobs

varunsharma07

683 karma · joined July 3, 2021

Founder of StepSecurity (https://www.stepsecurity.io)
submissionscomments
varunsharma07··on Keyv and friends compromised in active Shai-Hulud supply chain attack
We (StepSecurity) published a full analysis of both payload stages: https://www.stepsecurity.io/blog/chaindrop-npm-worm

Some additional detail from our analysis:

1. Provenance did not fail, it worked as designed and still shipped malware. The initial 11 packages were published through npm OIDC Trusted Publishing with valid SLSA attestations. The attacker compromised the maintainer's GitHub account and let the projects' own release workflows publish. Provenance proves which commit was built, not that the commit was authorized.

2. There is a booby trap on remediation: the worm installs a watcher that fires an attacker payload when the stolen GitHub token gets revoked. Remove the token monitor first, then rotate.

3. Persistence goes beyond node_modules. It writes .claude/settings.json (SessionStart hook) and .vscode/tasks.json (runOn: folderOpen), each re-executing the dropper. Check repo dotfiles too.

4. No C2 domain to sinkhole: exfil endpoints resolve at runtime from an Ethereum contract. Observed domain is npm-cache.com, but the operator can rotate it and push new code to infected hosts.

If you're auditing: look for setup.mjs, a 727,680 byte Math_Symbol.js (math_init.js in the second wave), and "preinstall": "node setup.mjs" in package.json. Careful, regenerate-unicode-properties ships a legitimate 1 KB Math_Symbol.js; the malicious one is over 700 KB.

Full IOC and package list in the post, updated as the campaign develops.

varunsharma07··on Multiple mastra NPM packages compromised
Mastra is an open-source TypeScript framework for building AI agents, workflows, and RAG pipelines.

The StepSecurity Threat Intelligence Team has identified that multiple mastra npm packages have been compromised.

varunsharma07··on Laravel-Lang Supply Chain Attack
On May 22, 2026, an attacker with push access to the Laravel-Lang GitHub organization rewrote every git tag across multiple popular Composer packages within a single 15 minute window.
varunsharma07··on Postmortem: TanStack NPM supply-chain compromise
We have built an AI Package Analyst https://app.stepsecurity.io/oss-security-feed and also monitor them using https://github.com/step-security/harden-runner for runtime behavior.
varunsharma07··on Postmortem: TanStack NPM supply-chain compromise
@mistralai/mistralai npm package was also compromised as part of this worm https://github.com/mistralai/client-ts/issues/217

It has been pulled from the npm registry now.

varunsharma07··on Postmortem: TanStack NPM supply-chain compromise
The Mini Shai-Hulud worm is actively compromising legitimate npm packages by hijacking CI/CD pipelines and stealing developer secrets. StepSecurity's OSS Package Security Feed first detected the attack in official @tanstack packages and is tracking its spread across the ecosystem in real time.
varunsharma07··on [dead]
The StepSecurity threat intelligence team discovered that dev-protocol — a verified GitHub organization with 568 followers belonging to a legitimate Japanese DeFi project — has been hijacked and is now being used to distribute malicious Polymarket trading bots.
varunsharma07··on Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push
An attacker is compromising hundreds of GitHub accounts and injecting identical malware into hundreds of Python repositories. The earliest injections date to March 8, 2026, and the campaign is still active with new repos continuing to be compromised.
varunsharma07··on Hackerbot-Claw: AI Bot Exploiting GitHub Actions – Microsoft, Datadog Hit So Far
The root cause is workflows that grant trust to untrusted inputs: pull_request_target that checks out and executes fork code with repo secrets, ${{ }} expressions that interpolate branch names/filenames into shell commands unsanitized, and issue_comment triggers with no author_association check.

These attacks only work when maintainers opt into dangerous patterns without guardrails.

varunsharma07··on Hackerbot-Claw: AI Bot Exploiting GitHub Actions – Microsoft, Datadog Hit So Far
We analyzed an autonomous bot (hackerbot-claw) that's actively scanning GitHub repos for exploitable Actions workflows. It hit Microsoft, DataDog, a CNCF project, and awesome-go (140k stars) achieving RCE in 4 out of 5 targets and exfiltrating a GITHUB_TOKEN. Full breakdown of the 5 attack techniques with evidence.
varunsharma07··on Cline Supply Chain Attack: Cline 2.3.0 Silently Installs OpenClaw
cline@2.3.0 was published with a malicious post-install script that silently installs OpenClaw on any machine running npm install.
varunsharma07··on Harden Runner Detected the SHA1-Hulud Supply Chain Attack in CNCF's Backstage
A case study on detecting npm supply chain attacks through runtime monitoring and baseline anomaly detection
varunsharma07··on Nx compromised: malware uses Claude code CLI to explore the filesystem
Thanks! I had also posted on HN 9 hours before this submission: https://news.ycombinator.com/item?id=45035115 Would be great if HN admins can update the link for this story
varunsharma07··on Popular Nx Build System NPM Package Compromised with Data Stealing Malware
Nx package on npm hijacked to steal cryptocurrency wallets, GitHub/npm tokens, SSH keys, and environment secrets through sophisticated exfiltration attack
varunsharma07··on Suspicious Tag Change in AWS's GitHub Action: What Happened and Why It Matters
How an AWS release rollback triggered the same red flags as a supply chain attack and why treating every semantic version tag change as suspicious is key to protecting your CI/CD pipelines
varunsharma07··on Num2words PyPI Package Compromised
Popular Python Package num2words v0.5.15 Published Without Repository Tag, Linked to Known Threat Actor
varunsharma07··on Tj-actions/changed-files GitHub Action Compromised – used by over 23K repos
I’m Varun, CEO & Co-Founder of StepSecurity. StepSecurity detected and reported the tj-actions/changed-files compromise and has been actively helping the community recover from this incident.

To support you in understanding what happened and recovering swiftly, we’re hosting an Office Hour:

Date: March 17, 2025 Time: 10:00 AM Pacific Time (PT) Add to your calendar: https://www.addevent.com/event/Tf25207322

varunsharma07··on Tj-actions/changed-files GitHub Action Compromised – used by over 23K repos
They were only printed to stdout and not sent out
varunsharma07··on Tj-actions/changed-files GitHub Action Compromised – used by over 23K repos
Great points! Harden-Runner (https://github.com/step-security/harden-runner) is similar to Firejail and OpenSnitch but purpose-built for CI/CD context. Harden-Runner detected this compromise due to an anomalous outbound network request to gist.githubusercontent.com.

Interestingly, Firejail itself uses Harden-Runner in its GitHub Actions workflows! https://github.com/search?q=repo%3Anetblue30%2Ffirejail%20ha...

varunsharma07··on Tj-actions/changed-files GitHub Action Compromised – used by over 23K repos
Yes, just prints to the build log, so the risk is higher for public repos. Lot of public repos have creds printed in their build logs due to this compromised action.
varunsharma07··on Tj-actions/changed-files GitHub Action Compromised – used by over 23K repos
https://github.com/tj-actions/changed-files/issues/2463
varunsharma07··on Tj-actions/changed-files GitHub Action Compromised – used by over 23K repos
What Happened? • The compromised Action executes a Python script that dumps CI/CD secrets from the Runner Worker process. • Multiple v35 tags were modified four hours ago, indicating a recent supply chain attack. • The malicious behavior can be observed in StepSecurity Harden-Runner insights, showing the Action downloading and executing an unauthorized script.
varunsharma07··on CI/CD supply chain attack on Azure Karpenter Provider open-source project
An independent security researcher, on August 31st, 2024, demonstrated a successful supply chain attack on Azure Karpenter Provider, an open-source project maintained by Microsoft. A vulnerable GitHub Actions workflow led to this attack. The researcher successfully exploited the vulnerability and gained access to the workflow's GITHUB_TOKEN, which had "id-token: write" permission to the repository.
varunsharma07··on Celebrating Success of 500 Open Source Projects Using StepSecurity's Platform
You can browse the pull requests created by the top 50 of the 500 open-source projects that have benefited from the platform at app.stepsecurity.io/securerepo/trending.
varunsharma07··on Show HN: SMS to Slack, receive 2FA codes in Slack
I am hesitant about sharing QR codes etc., with a 3rd party. I assume I would have to share the QR code with you, right?
varunsharma07··on Show HN: Quickly Create Security Tests for All Your APIs (YC S21)
Can tests be created automatically based on captured API traffic? Also, I have heard a bit about, but not read in detail about Nuclei: https://nuclei.projectdiscovery.io/templating-guide/. How does this compare with your solution?
varunsharma07··on Show HN: View the Mood of the World
Please see if you can add options for the feelings. It is easier to decide on a feeling when you see a list of options. It will also make aggregating easier.
varunsharma07··on Show HN: SMS to Slack, receive 2FA codes in Slack
Interesting. I have felt the need for this before. Do you also support authenticator app codes? I believe authenticator apps are recommended relative to SMS.
varunsharma07··on Show HN: Remove technical debt from Python Azure Functions
I was curious if this is missing across languages or just in Python.
varunsharma07··on Show HN: Remove technical debt from Python Azure Functions
Are there other similar libraries for Azure Functions for other languages?
Page 1 of 3Next →