Skip to main content
Security

Keyv and friends compromised in active Shai-Hulud supply chain attack

Keyv and friends compromised in active Shai-Hulud supply chain attack Image: Primary
Attackers compromised the GitHub account of the maintainer behind keyv on August 4, 2026, and used that access to inject a credential-stealing worm across the entire package family, the source said. The same maintainer owns cacheable, flat-cache, file-entry-cache, and several other widely-used caching utilities, all of which were swept up in the same attack. The compromise was carried out by pushing malicious files directly to the main branch and then immediately cutting a new release, meaning the poisoned versions were published to npm with valid provenance signed by GitHub Actions. Compromised packages include keyv 6.0.0, flat-cache 6.1.24, file-entry-cache 11.1.6, and numerous others. Every package in the family received two new files, setup.mjs and Math_Symbol.js, along with a preinstall script added to each package.json. Anyone who ran npm install against an affected version would have had setup.mjs execute automatically before their install completed. The payload harvests secrets from the victim's environment, encrypts the findings, and exfiltrates them to a public GitHub repository whose description reads "Shai-Hulud: Here We Go Again". Update August 4, 2026, 13:37 CEST: At least 434 packages across 1381 versions have been compromised by the worm, with a combined total of over 2 billion monthly installs at the time of writing. The payload also contains worm-like propagation functionality to infect packages of other maintainers that have installed one of the compromised packages.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from aikido.dev and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI
AI

Moonshot AI's Kimi K3 now available on Amazon Bedrock

AWS has made Kimi K3 from Moonshot AI available on Amazon Bedrock, describing it as the first open-weight model to reach 2.8 trillion parameters. The model combines native vision capabilities with a 1-million-token context window...

AI Infrastructure
AI Infrastructure

AWS launches GPU-aware SageMaker HyperPod Inference Gateway

AWS announced general availability of the SageMaker HyperPod Inference Gateway, a Kubernetes-native routing addon that places inference requests using real-time GPU signals such as KV cache utilization, queue depth, LoRA adapter r...

Security Products
Security Products

Microsoft investigates Windows 11 domain-trust failures

Microsoft is investigating reports that the Windows 11 KB5124008 security update breaks domain trust relationships on some enterprise systems, preventing valid domain users from signing in. Administrators reported that affected de...

Security
Security

Cisco patches max-severity ISE zero-day under active exploitation

Cisco released security updates for a maximum-severity authentication bypass in Identity Services Engine and ISE Passive Identity Connector, tracked as CVE-2026-76460, and said its Product Security Incident Response Team is aware ...

Security
Security

Cisco warns of actively exploited ISE authentication bypass

Cisco warned that CVE-2026-76460, a maximum-severity flaw in Identity Services Engine and ISE Passive Identity Connector, is being actively exploited. The reported API authentication-control weakness can let an unauthenticated rem...