Shai-Hulud npm Worm Infects Over 1,280 Packages
Shai-Hulud npm worm spread credential-stealing malware across over 1,280 packages.
A fast-moving software supply-chain attack has compromised Keyv and hundreds of other npm packages, exposing developer workstations and CI systems to credential-stealing malware. Aikido Security identified the malware as a Shai-Hulud variant. The attack was traced back to the GitHub account of Keyv maintainer Jared Wray. Attackers used GitHub Actions to publish Keyv version 6.0.0. The poisoned release carried valid provenance information on npm but did not verify the safety of the source code. Development teams should remove affected releases, rotate credentials, and scan for unauthorized access.