Threats Tagged 'software development'
View all threats tagged with 'software development'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'software development'
Click on any threat for detailed analysis and mitigation recommendations
Sha1-Hulud is a sophisticated new variant of an NPM supply chain attack that executes during the preinstall phase of popular packages like Postman, Zapier, and AsyncAPI. It harvests cloud credentials across AWS, Azure, and GCP, and establishes persistence by creating a self-hosted GitHub Actions runner named 'SHA1HULUD' with an injection-vulnerable workflow. This enables attackers to move laterally across cloud environments beyond the initial development environment. Immediate mitigation includes removing compromised packages, revoking and regenerating all tokens and credentials, and enforcing hardware-based MFA for developer accounts. The attack leverages multiple MITRE ATT&CK techniques related to execution, persistence, credential access, and lateral movement. No known exploits in the wild have been reported yet, but the threat poses a medium severity risk due to its potential impact on cloud infrastructure security and software supply chains. Join the discussion | AlienVault OTX General | 11/27/2025, 14:13:07 UTC Added: 11/27/2025, 18:38:55 UTC |
Showing 1 to 1 of 1 result