ON
← Back to feed
Supply chain attack on keyv: Shai Hulud worm infected more than 440 npm packets
Germany💻 Technology4 hr. ago

Supply chain attack on keyv: Shai Hulud worm infected more than 440 npm packets

A supply chain attack targeting the keyv key-value database and related npm packages occurred on August 4th, when the maintainer's GitHub account was compromised. The attack involved malicious versions of over 440 npm packages, which were distributed through the package ecosystem. These packages contained hidden malware that automatically executed during installation, downloading the Bun JavaScript runtime and running additional malicious code. The malware collected sensitive data such as GitHub tokens, npm credentials, cloud service keys, and other access information, encrypting and uploading them to publicly accessible GitHub repositories controlled by attackers. The attack is part of a series of Shai-Hulud supply chain attacks, including previous incidents involving SAP, TanStack, and Red Hat.

Go to the primary sources (4)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenter4 hr. ago
Supply chain attack on keyv: Shai Hulud worm infected more than 440 npm packets

A supply chain attack targeting the keyv key-value database and related npm packages occurred on August 4th, when the maintainer's GitHub account was compromised. The attack involved malicious versions of over 440 npm packages, which were distributed through the package ecosystem. These packages contained hidden malware that automatically executed during installation, downloading the Bun JavaScript runtime and running additional malicious code. The malware collected sensitive data such as GitHub tokens, npm credentials, cloud service keys, and other access information, encrypting and uploading them to publicly accessible GitHub repositories controlled by attackers. The attack is part of a series of Shai-Hulud supply chain attacks, including previous incidents involving SAP, TanStack, and Red Hat.

Bias read (Center): The article focuses on a technical cybersecurity incident involving software supply chain vulnerabilities. It provides detailed descriptions of the attack mechanism, affected packages, and the broader context of similar attacks. There is no political framing, bias, or emphasis on any particular side

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories