The Hacker Group Turning Supply Chain Attacks Into a Sport | Threat Wire

Hak5
Hak5May 22, 2026

Why It Matters

Turning supply‑chain exploits into a prize‑driven contest amplifies risk, forcing firms to harden token hygiene and package‑registry defenses before attackers monetize widespread code contamination.

Key Takeaways

  • Mini Shai Hulud worm open‑sourced, $1,000 bounty for biggest supply‑chain attack
  • RubyGems suffered a spam‑publish DDoS, disabling new account registrations
  • 84 versions injected into TanStack NPM packages via PR and token tricks
  • Worm includes geographic roulette kill switch that can erase targeted systems
  • OpenAI rotated signing certificates after worm infected two employee machines

Summary

The episode spotlights a new wave of software supply‑chain abuse centered on the open‑sourced “mini Shai Hulud” worm. Its creators have partnered with Breach Forums to award a $1,000 crypto prize to the attacker who generates the most downstream package downloads, effectively turning a destructive worm into a competition.

In the same week RubyGems endured a coordinated spam‑publish DDoS that forced the registry to suspend new account creation and purge over 500 malicious packages. Meanwhile, the TanStack JavaScript namespace saw 84 malicious versions pushed through a forged pull‑request and GitHub Actions cache‑poisoning technique, affecting 42 packages and later expanding to 373 packages across 169 namespaces.

Team PCP added a whimsical twist: a “roulette.py” module that reads time‑zone and language data, rolls a die, and, on a hit, plays loud music before executing an rm‑rf on systems in targeted regions. The worm also installs a dead‑man‑switch monitor that self‑destructs if its GitHub token is revoked, a behavior documented by JFrog and upwind.io.

These incidents underscore the fragility of the JavaScript ecosystem, where millions of projects rely on NPM and rapid package publishing. Organizations must enforce strict token management, implement robust rate‑limiting, and treat supply‑chain threats as a core risk, especially as attackers monetize exploits through bounties and public competitions.

Original Description

⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️
@endingwithali →
Everywhere else: https://links.ali.dev
Want to work with Ali? hak5@endingwithali.com
[❗] Join the Patreon→ https://patreon.com/threatwire
00:00 0 - Intro
00:33 1 - iPhones And Android E2EE
08:39 2 - Package Managers Are On Fire
09:45 3 - BSides
11:24 4 - Outro
LINKS
🔗 Story 1: iPhones And Android E2EE
🔗 Story 2: Package Managers Are On Fire
🔗 Story 3: BSides
-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
____________________________________________
Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.

Comments

Want to join the conversation?

Loading comments...