securityonline.info 8/4/2026, 3:08:44 PM · external

npm Supply Chain Attack Hijacks Keyv, Spreads Shai-Hulud Malware

npm Supply Chain Attack Hijacks Keyv, Spreads Shai-Hulud Malware
CyberSIXT Evidence Panel
Primary Source aikido.dev

A recent npm supply chain attack has exploited a vulnerability in the Keyv package, resulting in the deployment of the Shai-Hulud malware. The attack, linked to compromised GitHub maintainer accounts, targeted npm and JavaScript developers through poisoned package versions. Notably, the attack allows for the theft of various credentials, including AWS and GitHub tokens, leading to widespread exposure given Keyv's substantial download rate of 127 million weekly.

To combat this threat, affected parties are advised to remove compromised packages and rotate their secrets. Security experts emphasize the importance of verifying package provenance to prevent future attacks.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline