
Shai-Hulud Supply Chain Attack Compromises Keyv and Hundreds of npm Packages
Attackers have compromised the GitHub account of a Keyv maintainer, a widely used JavaScript key-value storage library, to distribute credential-stealing malware via npm packages. This ongoing supply chain attack, known as the Shai-Hulud campaign, has affected Keyv and several related caching libraries, with a combined monthly installation reach in the billions. Aikido Security reported that […]
The post Shai-Hulud Supply Chain Attack Compromises Keyv and Hundreds of npm Packages appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.