TGViewer
Doprax Doprax @dopraxcloud · 2.49K subscribers
Post #46 3.04K
npm supply-chain worm hits 169+ packages.

The Mini Shai-Hulud worm (TeamPCP) compromised TanStack Router, UiPath, Mistral AI, Guardrails AI, and 165+ other npm packages. 373 malicious versions.
It hijacks CI/CD via GitHub Actions cache poisoning, steals credentials, and installs a daemon polling GitHub every 60s. If the daemon sees a revoked token, it runs rm -rf ~/. Cleanup order matters.

Running Node.js on a Doprax VM:
1. npm ls | grep -E '@tanstack|@uipath|@mistralai|guardrails'
2. npm audit
3. If hit: stop gh-token-monitor BEFORE rotating tokens
4. Wipe node_modules, reinstall with --ignore-scripts
5. Rotate every credential that touched the VM

Prevention: pnpm 11 defaults (minimumReleaseAge: 1440, blockExoticSubdeps, no install scripts) would have blocked this.
Isolated VMs keep the blast radius at one machine. Core Doprax is unaffected.

Full guide: https://www.doprax.com/blog/an-npm-worm-is-spreading-heres-what-to-do-if-you-run-node-on-doprax
More from @dopraxcloud
  1. Sep 28, 2026IPv4 addresses are limited, so providers reuse them. If a past owner sent spam, attacked o…
  2. Sep 24, 2026Not sure which port to run your service on? Quick answer, with the reasons: → Use 443 (HTT…
  3. Sep 22, 2026When the network is unstable, your service or app will sometimes be offline or unavailable…
  4. Sep 17, 2026As we mentioned previously, ProVM now supports up to 5 additional IPs per VM, which means…
  5. Sep 12, 2026We’ve reactivated the “pay by card” payment method! You can now pay with credit card, Goog…
  6. Sep 9, 2026VPN apps collect data about their users. That’s because in addition to offering a tunnel,…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →