The Shai-Hulud npm worm didn't fake its security check — it earned a legitimate one
Source:
ventureBeat
August 5, 2026 · 09:12
An attacker on Tuesday took over the GitHub account of the developer who maintains keyv, a small key-value storage library that npm serves roughly 127 million times a week. Within hours, poisoned versions of keyv and its sibling caching packages were live on npm, carrying a credential-stealing worm. By midday, security firm Aikido counted at least 868 compromised packages across 1,381 versions, together carrying over two billion monthly installs, a total still climbing. JFrog independently traced the campaign across more than 400 packages and 1,700 poisoned versions. The part that should worry every security team is not the download count. It is the paperwork. The initial poisoned releases shipped with valid provenance signatures, the cryptographic attestation the industry built to prove a…
The original article opens on the publisher's website.
More from Automotive
View topic →Larry Page’s flying car company Pivotal loses its CEO
techcrunch
Sep 1, 2026 · 16:59
SEC proposes transfer agent rule, sets event to figure out round-the-clock U.S. trading
coinDesk
Sep 1, 2026 · 16:55
The Range Rover Electric: Specs, Price, Availability
wired
Sep 1, 2026 · 16:01
Android stuck in Safe Mode? Here's how to turn it off
engadget
Sep 1, 2026 · 16:00
How to change the background on iPhone Messages
engadget
Sep 1, 2026 · 15:30
Countries mentioned