DigiNews

Tech Watch by Johan Denoyer

← Back to articles

Keyv and friends compromised in active Shai-Hulud supply chain attack

Quality: 8/10 Relevance: 9/10

Summary

An active npm supply chain attack compromised the keyv ecosystem and related packages, injecting credential-stealing malware into the npm index. The attack used a GitHub account takeover to push malicious files (setup.mjs and Math_Symbol.js) and a preinstall script, exfiltrating tokens and secrets from victims. By the report, 868 packages across 1381 versions were affected, with over 2 billion monthly installs, highlighting a major risk to the JavaScript supply chain and the need for rapid remediation and monitoring.

🚀 Service construit par Johan Denoyer