Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Meetily Lets You Transcribe and Summarize Meetings Without a Subscription—Here’s How

    August 9, 2026

    These AI Barons Are Ready to Give Away Their Fortunes

    August 9, 2026

    This Week’s Awesome Tech Stories From Around the Web (Through August 8)

    August 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Meetily Lets You Transcribe and Summarize Meetings Without a Subscription—Here’s How
    • These AI Barons Are Ready to Give Away Their Fortunes
    • This Week’s Awesome Tech Stories From Around the Web (Through August 8)
    • How to Disable Gemini in Gmail and Google Docs
    • How ideas of a vast censorship network moved from the online fringe to Trump policy
    • The Pivot From Tech Expert to Organizational Leader
    • Scientists Used AI to Create 16 New Viruses
    • The Download: a censorship conspiracy theory and the first virus created by AI
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Hackers can bypass npm’s Shai-Hulud defenses via Git dependencies
    Cybersecurity

    Hackers can bypass npm’s Shai-Hulud defenses via Git dependencies

    kirklandc008@gmail.comBy kirklandc008@gmail.comJanuary 26, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Hackers can bypass npm’s Shai-Hulud defenses via Git dependencies
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The defense mechanisms that NPM introduced after the ‘Shai-Hulud’ supply-chain attacks have weaknesses that allow threat actors to bypass them via Git dependencies.

    Collectively called PackageGate, the vulnerabilities were discovered in multiple utilities in the JavaScript ecosystem that allow managing dependencies, like pnpm, vlt, Bun, and NPM.

    Researchers at endpoint and supply-chain security company Koi discovered the issues and reported them to the vendors. They say that the problems were addressed in all tools except for NPM, who closed the report stating that the behavior “works as expected.”

    Script execution bypass

    The self-spreading Shai-Hulud supply-chain attack initially impacted npm in mid-September 2025 and compromised 187 packages. A month later, the attack returned in a new 500-package wave, which was later evaluated to have exposed 400,000 developer secrets in over 30,000 auto-generated GitHub repositories.

    In response to the Shai-Hulud attacks and other supply-chain incidents such as “s1ngularity” and “GhostAction,” GitHub, the operator of NPM, announced a plan to implement additional security measures and suggested several mitigations.

    Among them are recommendations to disable lifecycle scripts during installation (‘–ignore-scripts=true’) and to enable lockfile integrity and dependency pinning.

    Koi security researchers found that when NPM installs a dependency from a Git repository, configuration files such as a malicious ‘.npmrc’ can override the git binary path, leading to full code execution even when the ‘—ignore-scripts’ flag is set to ‘true.’

    “We have evidence that actors published a proof-of-concept abusing this technique to create a reverse shell in the past,” warned the researchers, highlighting that the problem isn’t just theoretical.

    For the other JavaScript package managers, a bypass of the script execution security measure is achieved via separate mechanisms, plus for pnpm and vlt, a lockfile integrity bypass is also possible.

    Bun patched the flaws impacting it in version 1.3.5, vlt patched within days after Koi reached out, and pnpm released fixes for two flaws tracked under CVE-2025-69263 and CVE-2025-69264.

    NPM’s response

    Koi Security filed their findings in a vulnerability report submitted to NPM’s HackerOne, as the bug bounty scope explicitly covers script execution with ‘—ignore-scripts.’

    Despite that, npm rejected the report on the grounds that users are responsible for vetting the content of packages they install, and did not respond to multiple follow-up efforts made by the researchers.

    BleepingComputer contacted GitHub for a statement on the matter and a spokesperson said that they are working to address the issue as npm is actively scanning the registry for malware. 

    “The security of the npm ecosystem is a collective effort, and we strongly encourage projects to adopt trusted publishing and granular access tokens with enforced two-factor authentication to fortify the software supply chain,” the GitHub spokesperson told BleepingComputer.

    As MCP (Model Context Protocol) becomes the standard for connecting LLMs to tools and data, security teams are moving fast to keep these new services safe.

    This free cheat sheet outlines 7 best practices you can start using today.

    Download Now

    bypass defenses dependencies Git hackers npms ShaiHulud
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Meetily Lets You Transcribe and Summarize Meetings Without a Subscription—Here’s How
    • These AI Barons Are Ready to Give Away Their Fortunes
    • This Week’s Awesome Tech Stories From Around the Web (Through August 8)
    • How to Disable Gemini in Gmail and Google Docs
    • How ideas of a vast censorship network moved from the online fringe to Trump policy

    Meetily Lets You Transcribe and Summarize Meetings Without a Subscription—Here’s How

    August 9, 2026

    These AI Barons Are Ready to Give Away Their Fortunes

    August 9, 2026

    This Week’s Awesome Tech Stories From Around the Web (Through August 8)

    August 8, 2026

    How to Disable Gemini in Gmail and Google Docs

    August 8, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.