
Shai-Hulud Returns With Self-Propagating npm Worm Targeting Developer Credentials
The campaign, detected on August 4, 2026, targeted the maintainer of Keyv, a widely used JavaScript key-value storage library. The scale of the incident is concerning. Keyv recorded more than 600 million downloads last month. Related packages affected by the maintainer’s ecosystem include flat-cache, with nearly 580 million downloads, cacheable-request with more than 137 million, […]
The post Shai-Hulud Returns With Self-Propagating npm Worm Targeting Developer Credentials appeared first on Cyber Security News.