npm Supply Chain Attack: 868 Packages Infected with Credential-Stealing Worm

A major npm supply chain attack compromised keyv and other popular packages, infecting 868 packages with credential-stealing worms, affecting millions of downloads; developers urged to act.

2026-08-04 ~ 2026-08-04 · 3 related posts