MICROSOFT Threat Intelligence has identified a large-scale npm supply chain attack affecting over 400 packages from various publishers, deploying a self-propagating worm called Mini Shai-Hulud. This malware executes via an npm preinstall hook, allowing it to steal credentials from developer environments. It propagates by modifying and republishing packages, thereby creating a rapid dissemination of malicious releases.
Key mitigation strategies involve updating npm, reviewing dependency trees, rotating credentials, and using Microsoft Defender products for protection and detection. Awareness of this attack is vital for organizations to prevent compromise and ensure a secure development environment.