The Technology
The Shai-Hulud Supply Chain Attack Compromises Keyv and Related Packages
Researchers say the active Shai-Hulud supply chain campaign has compromised Keyv and a cluster of related npm packages, injecting code that harvests credentials from developer machines and CI systems and then uses them to publish further malicious versions. The self-propagating design is what makes this class of attack hard to contain: each stolen token becomes a new publishing identity. Maintainers are being urged to rotate tokens and audit recent installs.
Read Full Story at aikido.devDiscussSoon← Front Page