Hackers Poison Trusted Software Updates to Steal Developer and Cloud Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Hackers are turning trusted software updates into a route for stealing developer and cloud credentials. Recent supply chain incidents show how a single altered package, build action, or publishing token can place malware inside routine development workflows.

The risk is not limited to one product or programming community. After obtaining a maintainer token or access to an automated release pipeline, attackers can deliver code through an update that users and security tools may already trust.

ReversingLabs said in a report shared with Cyber Security News (CSN) that S1ngularity, Shai-Hulud, and TeamPCP show how quickly a compromise can spread from one supplier to many downstream organizations.

The report describes a chain of stolen credentials, poisoned releases, and repeat attacks across open source ecosystems.

The consequences reach beyond a developer laptop. Stolen GitHub, npm, cloud, and SSH credentials can expose source code, cloud resources, deployment systems, and other packages. In several cases, malware used credentials taken from one victim to publish the next poisoned update.

Hackers Poison Trusted Software Updates

The S1ngularity incident illustrates why trusted software distribution is a valuable target. Attackers compromised Nx packages after using a crafted pull request to obtain a token, replace a CI script, and trigger a publishing workflow.

The infected packages then ran post-install hooks on developer machines, a pattern detailed in CSN’s coverage of Nx package credential theft during the 2025 campaign.

Those hooks searched for valuable data, including tokens, credentials, and SSH keys. They also used GitHub credentials found on the host to create public repositories, giving the attackers a direct route to retrieve stolen material.

The campaign was unusual because its malicious code also prompted local AI tools to search the file system for likely credential locations.

The report, published September 30, 2026, places the Nx compromise on August 26, 2025. It treats the original campaigns separately from TeamPCP, whose involvement in earlier incidents remains unproven.

S1ngularity sample code showing the usage of “s1ngularity-repository” as the attacker’s exfiltration vector (Source - RevrsingLabs)
S1ngularity sample code showing the usage of “s1ngularity-repository” as the attacker’s exfiltration vector (Source – RevrsingLabs)

The report says the prompts sought leads to GitHub and npm tokens, cloud credentials, and SSH keys. This makes the attack more than a conventional password stealer: it attempted to turn a developer’s own assistant into a local discovery tool.

Readers can see the broader impact in AI tool credential targeting, including the data the malware sought from affected systems.

S1ngularity also showed why long-lived publishing tokens are risky. The stolen npm token enabled infected packages to be released, while compromised updates gained the benefit of an established package’s reputation.

Nx later adopted a trusted-publisher approach using short-lived, per-run credentials, reducing the value of a token stolen from a repository.

Credential Worms

Shai-Hulud expanded this model by making it self-propagating. The worm searched compromised systems for npm publishing credentials, used them to identify packages a victim could publish, and inserted malicious code into further releases.

That let it spread without a separate software flaw at each target, as explained in the Shai-Hulud worm attack investigation. Later activity attributed to or associated with TeamPCP showed how attackers can reuse an earlier breach.

In the Trivy incident, a privileged token was extracted in February 2026, but incomplete credential rotation left a path for attackers to publish a malicious update on March 19 through an automated system.

The attackers altered version tags used by CI/CD workflows, a technique covered in CSN’s report on Trivy tag poisoning attack. The credential-stealing payload targeted running workflows, where secrets can be especially valuable.

After the Trivy compromise, the group used harvested npm tokens to distribute CanisterWorm, which compromised more than 60 npm packages. Checkmarx, LiteLLM, and Telnyx were also affected, showing how stolen access can support successive intrusions.

Organizations should treat a poisoned update as a potential full credential compromise. They should replace long-lived publishing secrets with short-lived credentials, tightly limit token permissions, pin CI/CD dependencies to reviewed commits, and monitor publishing and repository activity for unexpected changes.

Teams that may have run an affected release should rotate exposed tokens promptly and check for unauthorized repositories, workflows, and package publications.

Indicators of compromise (IoCs):-

Type Indicator Description
Repository name s1ngularity-repository Public GitHub repository name used by S1ngularity to expose stolen information
SHA-1 sample hash d2438106211ebd12c4f0a248848bc9864c97a3c0 S1ngularity malware sample referenced in the source
SHA-1 sample hash b4f20b39aa6df1002872f07973024d85aa49abaf S1ngularity malware sample referenced in the source
SHA-1 sample hash 2379ac0e03b1a67c4ca5693136eff4945e644a91 S1ngularity malware sample referenced in the source
SHA-1 sample hash e5d1f3c45ee7cca6ae59cf64e0573050bbe136ec S1ngularity malware sample referenced in the source

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Hackers Poison Trusted Software Updates to Steal Developer and Cloud Credentials appeared first on Cyber Security News.