Attackers have compromised the GitHub account of a Keyv maintainer, a widely used JavaScript key-value storage library, to distribute credential-stealing malware via npm packages. This ongoing supply chain attack, known as the Shai-Hulud campaign, has affected Keyv and several related caching libraries, with a combined monthly installation reach in the billions. Aikido Security reported that […] The post Shai-Hulud Supply Chain Attack Compromises Keyv and Hundreds of npm Packages appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
First seen on gbhackers.com
Jump to article: gbhackers.com/shai-hulud-supply-chain-attack-compromises-keyv/
![]()

