Keyv and friends compromised in npm supply chain attack

Lobsters·5 points·dbremner·about 2 months ago·aikido.dev

Mini Shai-Hulud malware was injected into keyv and eight related npm packages on August 4, 2026 after an attacker compromised the maintainer's GitHub account

Read the full article at aikido.dev →

Related stories

Related topics