A supply chain attack targeting the keyv key-value database and related npm packages occurred on August 4th, when the maintainer's GitHub account was compromised. The attack involved malicious versions of over 440 npm packages, which were distributed through the package ecosystem. These packages contained hidden malware that automatically executed during installation, downloading the Bun JavaScript runtime and running additional malicious code. The malware collected sensitive data such as GitHub tokens, npm credentials, cloud service keys, and other access information, encrypting and uploading them to publicly accessible GitHub repositories controlled by attackers. The attack is part of a series of Shai-Hulud supply chain attacks, including previous incidents involving SAP, TanStack, and Red Hat.
Bias read (Center): The article focuses on a technical cybersecurity incident involving software supply chain vulnerabilities. It provides detailed descriptions of the attack mechanism, affected packages, and the broader context of similar attacks. There is no political framing, bias, or emphasis on any particular side





