Keyv npm Package with 127M Weekly Downloads Compromised in Shai-Hulud Attack

Attackers have compromised the GitHub account of the maintainer behind keyv, a popular key-value storage library that pulls in roughly 127 million weekly downloads on npm, and used that access to push credential-stealing malware across the maintainer’s entire package portfolio. The breach, which unfolded on August 4, 2026, marks one of the largest npm supply […]

This article has been indexed from Cyber Security News

Read the original article: