Kryptovaluta-ticker:
sysadmin fra Cyber Security News

Keyv npm Package with 127M Weekly Downloads Compromised in Shai-Hulud Attack

Guru Baran
15 hours ago
5 Visninger
0 Kommentarer
Keyv npm Package with 127M Weekly Downloads Compromised in Shai-Hulud Attack

Attackers have compromised the GitHub account of the maintainer behind keyv, a popular key-value storage library that pulls in roughly 127 million weekly downloads on npm, and used that access to push credential-stealing malware across the maintainer’s entire package portfolio. The breach, which unfolded on August 4, 2026, marks one of the largest npm supply chain incidents to date, with the malicious code spreading like a worm to hundreds of unrelated packages within hours. Research on the incident was exclusively shared with Cybersecuritynews by Aikido. The same maintainer behind keyv also owns several other heavily used caching utilities, including cacheable (29 million downloads a month), flat-cache (565 million downloads a...

Læs hele artiklen hos kilden.

Deltag i diskussionen — kommenter, stem og del links.

Registrer
Var dette nyttigt?
Del:

Kommentarer (0)

Log venligst ind eller opret dig for at deltage i diskussionen

Ingen kommentarer ennå. Bli den første til å kommentere!