
Keyv npm Package with 127M Weekly Downloads Compromised in Shai-Hulud Attack
Attackers have compromised the GitHub account of the maintainer behind keyv, a popular key-value storage library that pulls in roughly 127 million weekly downloads on npm, and used that access to push credential-stealing malware across the maintainer’s entire package portfolio. The breach, which unfolded on August 4, 2026, marks one of the largest npm supply […]
The post Keyv npm Package with 127M Weekly Downloads Compromised in Shai-Hulud Attack appeared first on Cyber Security News.