Keyv and friends compromised in active Shai-Hulud supply chain attack
Summary
An active npm supply chain attack compromised the keyv ecosystem and related packages, injecting credential-stealing malware into the npm index. The attack used a GitHub account takeover to push malicious files (setup.mjs and Math_Symbol.js) and a preinstall script, exfiltrating tokens and secrets from victims. By the report, 868 packages across 1381 versions were affected, with over 2 billion monthly installs, highlighting a major risk to the JavaScript supply chain and the need for rapid remediation and monitoring.