A Mini Shai-Hulud worm spread through more than 400 npm packages, stealing npm, GitHub, cloud, and CI/CD credentials.
CrowdStrike Holdings, Inc. (NASDAQ:CRWD) said on August 3 that a North Korea-linked adversary injected a malicious dependency ...
A hijacked GitHub account let the Shai-Hulud worm pass npm's trust check, spreading through packages with 2 billion monthly ...
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
npm granular access tokens configured to bypass 2FA can no longer create tokens, change maintainers, or manage org membership as of July 31, 2026 — closing the attack chain TeamPCP exploited across ...
Upwind identified a malicious release of keyv@6.0.0 that harvested AWS, GitHub, and npm credentials via a hidden preinstall script. With 154 million weekly downloads, the compromise had ecosystem-wide ...
A Keyv-linked npm worm poisoned 353 versions across 79 package names, stealing developer and CI credentials while repository ...
Inside these files—mainly the manifest (package.json) and index.js, there is nothing phenomenally interesting, just skeleton code. The manifest does pull in a bunch of development dependencies ...
Four packages containing highly obfuscated malicious Python and JavaScript code were discovered this week in the Node Package Manager (npm) repository. According to a report from Kaspersky, the ...
OAKLAND, Calif.--(BUSINESS WIRE)--npm, Inc., which runs the world’s largest software registry and maintains the npm software package management application, today announced the acquisition of ^Lift ...