| |
Keyv and friends compromised in active Shai-Hulud supply chain attack
On August 4, 2026, attackers compromised the GitHub account of the keyv library maintainer and injected a credential-stealing worm across eight packages and their dependents, affecting over 2 billion monthly installs combined. The malicious code was distributed through legitimate npm releases with valid GitHub Actions signatures, automatically executing a dropper script during installation that harvested secrets and propagated the worm to other packages. At least 868 packages across 1,381 versions were compromised in the active supply chain attack dubbed "Shai-Hulud."
Read Full Article →
← More Tech news