💻
npm worm "Shai-Hulud" infected packages with 2 billion monthly installs using legitimate signatures
💻 Technology

npm worm "Shai-Hulud" infected packages with 2 billion monthly installs using legitimate signatures

An attacker hijacked the GitHub account of the developer behind keyv, an npm library downloaded ~127 million times a week, and within hours pushed credential-stealing poisoned versions of keyv and related caching packages. Aikido Security counted at least 868 compromised packages across 1,381 versions with over two billion combined monthly installs. The most alarming detail: the malicious releases carried valid provenance signatures — the attacker earned them legitimately rather than forging them, undermining a key supply-chain security guarantee.

Comments

No comments yet