Hacker News·3 min read·hard

Keyv and friends compromised in active Shai-Hulud supply chain attack

C
cimi_
Keyv and friends compromised in active Shai-Hulud supply chain attack
AI Summary

A massive supply chain attack has compromised over 800 npm packages, including widely used utilities like Keyv, by injecting credential-stealing malware. The attackers used a compromised maintainer account to push malicious code that executes a dropper during installation.

On August 4, 2026, attackers compromised the GitHub account of the maintainer behind keyv , a key-value storage library with roughly 127 million weekly npm downloads, and used that access to inject credential-stealing malware across the entire package family. The same maintainer owns cacheable (29M downloads/month), flat-cache (565M downloads/month), file-entry-cache (557M downloads/month), and several other widely-used caching utilities, all of which were swept up in the same attack. The compromise was carried out by pushing malicious files directly to the main branch and then immediately cutting a new release, meaning the poisoned versions were published to npm with valid provenance signed by GitHub Actions.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologybusiness

Get the full story

Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.

Create free account

Already have an account? Sign in

Keyv and friends compromised in active Shai-Hulud supply chain attack — Headlinne — headlinne