keyv and cacheable npm Package Hijacked in Supply Chain Attack
wiz.io | incident | #ai-security | #supply-chain | #malware | #credential-theft | #npm | #shai-hulud | #keyv | #wiz
Summary
Wiz: keyv/cacheable packages were hijacked via a maintainer account; a Mini Shai-Hulud descendant hit 400+ packages, stealing credentials, AI configs and wallets; C2 via an Ethereum contract.
- Published
- Collected
Skip to content