A Mini Shai-Hulud worm spread through more than 400 npm packages, stealing npm, GitHub, cloud, and CI/CD credentials.
A hijacked GitHub account let the Shai-Hulud worm pass npm's trust check, spreading through packages with 2 billion monthly ...
CrowdStrike Holdings, Inc. (NASDAQ:CRWD) said on August 3 that a North Korea-linked adversary injected a malicious dependency ...
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
npm granular access tokens configured to bypass 2FA can no longer create tokens, change maintainers, or manage org membership as of July 31, 2026 — closing the attack chain TeamPCP exploited across ...
A Keyv-linked npm worm poisoned 353 versions across 79 package names, stealing developer and CI credentials while repository ...
Upwind identified a malicious release of keyv@6.0.0 that harvested AWS, GitHub, and npm credentials via a hidden preinstall script. With 154 million weekly downloads, the compromise had ecosystem-wide ...
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
A self-spreading worm poisoned hundreds of npm packages in hours, slipped past provenance checks, hid its controls on Ethereum, and hunted AI-tool keys.
Inside these files—mainly the manifest (package.json) and index.js, there is nothing phenomenally interesting, just skeleton code. The manifest does pull in a bunch of development dependencies ...
OAKLAND, Calif.--(BUSINESS WIRE)--npm, Inc., which runs the world’s largest software registry and maintains the npm software package management application, today announced the acquisition of ^Lift ...