Keyv and friends compromised in active Shai-Hulud supply chain attack

Keyv and friends compromised in active Shai-Hulud supply chain attack

On August 4, 2026, attackers hijacked the GitHub account of the maintainer behind keyv, a key-value storage library with ~127M weekly npm downloads, and injected credential-stealing malware across the entire package family, including cacheable, flat-cache, and file-entry-cache. The malicious files were pushed directly to the main branch and released with valid provenance. At least 868 packages (1,381 versions) were compromised, totaling over 2 billion monthly installs. The malware steals npm tokens, GitHub CLI tokens, AWS keys, and Vault tokens, and spreads worm-like to other packages.

At least 868 packages (across 1381 versions) have been compromised by the worm, with a combined total of over 2 billion monthly installs at the time of writing.

More from this day

2026-08-04