Attackers Compromised Keyv and Cacheable Source or Release Credentials. A self-replicating npm worm linked by tradecraft to Shai-Hulud has compromised more than 2,000 versions of 444 packages, stealing cloud and CI credentials and using exposed publisher tokens to spread through trusted dependencies.
First seen on govinfosecurity.com
Jump to article: www.govinfosecurity.com/worm-targets-more-than-2000-npm-package-versions-a-32412
![]()

