npm Supply Chain Attack Hits 868+ Packages With Credential-Stealing Worm
RSync25 · x · 2026-08-04
An active npm supply chain attack has compromised at least 868 packages with over 2 billion monthly downloads. The attack originated from the compromised GitHub account of the maintainer behind keyv, a popular library with roughly 127 million weekly downloads.
By utilizing a preinstall hook triggered during npm install, the attack drops the Shai-Hulud credential-stealing worm. The malware sweeps secrets from npm, GitHub, AWS, Kubernetes, and Vault, and then automatically spreads to infect other maintainers.
More from coding & agent
- Active npm Supply Chain Attack: keyv and Core Packages Hit by Credential-Stealing Worm — DanielLockyer · 2026-08-04
- Multi-Agent Workflow: Making Cursor and Codex Talk to Fix Bugs Together — kevinkern · 2026-08-04
- Dropping Turn Detectors: Letting LLMs Use Semantic Power for Barge-in — juberti · 2026-08-04
- Code Review is an Intuition Skill: Train It with Gamified Exercises — arekusandr_ · 2026-08-04
- LangChain Launches LangSmith LLM Gateway Public Beta for Agent Runtime Controls — LangChain · 2026-08-04
- Vibe Coding Pain Point: How to Track AI Agent Code Changes? — pacifio · 2026-08-04