Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Keyv and friends compromised in active Shai-Hulud supply chain attack

Summary

Attackers hijacked the maintainer account behind keyv (127M weekly downloads) and its caching-package family, injecting a credential-stealing Shai-Hulud worm that spread to 444+ npm packages.
Published
Collected

original ↗