npm Supply Chain Attack Hits 868+ Packages With Credential-Stealing Worm

RSync25 · x · 2026-08-04

An active npm supply chain attack has compromised at least 868 packages with over 2 billion monthly downloads. The attack originated from the compromised GitHub account of the maintainer behind keyv, a popular library with roughly 127 million weekly downloads.

By utilizing a preinstall hook triggered during npm install, the attack drops the Shai-Hulud credential-stealing worm. The malware sweeps secrets from npm, GitHub, AWS, Kubernetes, and Vault, and then automatically spreads to infect other maintainers.

Original post →

More from coding & agent

coding & agent channel →