npm supply-chain worm hits 169+ packages.
The Mini Shai-Hulud worm (TeamPCP) compromised TanStack Router, UiPath, Mistral AI, Guardrails AI, and 165+ other npm packages. 373 malicious versions.
It hijacks CI/CD via GitHub Actions cache poisoning, steals credentials, and installs a daemon polling GitHub every 60s. If the daemon sees a revoked token, it runs rm -rf ~/. Cleanup order matters.
Running Node.js on a Doprax VM:
1. npm ls | grep -E '@tanstack|@uipath|@mistralai|guardrails'
2. npm audit
3. If hit: stop gh-token-monitor BEFORE rotating tokens
4. Wipe node_modules, reinstall with --ignore-scripts
5. Rotate every credential that touched the VM
Prevention: pnpm 11 defaults (minimumReleaseAge: 1440, blockExoticSubdeps, no install scripts) would have blocked this.
Isolated VMs keep the blast radius at one machine. Core Doprax is unaffected.
Full guide: https://www.doprax.com/blog/an-npm-worm-is-spreading-heres-what-to-do-if-you-run-node-on-doprax
Post #46
3.04K
