News Score: Score the News, Sort the News, Rewrite the Headlines

Keyv and friends compromised in active Shai-Hulud supply chain attack

On August 4, 2026, attackers compromised the GitHub account of the maintainer behind keyv, a key-value storage library with roughly 127 million weekly npm downloads, and used that access to inject a credential-stealing worm across the entire package family. The same maintainer owns cacheable (29M downloads/month), flat-cache (565M downloads/month), file-entry-cache (557M downloads/month), and several other widely-used caching utilities, all of which were swept up in the same attack. The compromi...

Read more at aikido.dev

© News Score  score the news, sort the news, rewrite the headlines