Massive Supply-Chain Attack Hits 860+ npm Packages in Under Four Hours
A GitHub account hijack spread malware across 860 npm packages, exploiting credentials and crypto wallets within hours.
By
Content Team
ON THIS PAGE
Want more insights like this?
Subscribe to our newsletter to get the latest software protection strategies delivered to your inbox.
By submitting your email, you consent to Codekeeper contacting you and agree to our privacy policy.
A single attacker hijacked a GitHub maintainer account early Tuesday and unleashed self-replicating malware that infected more than 860 npm packages with over 2 billion combined monthly installs — all within four hours. The worm first hit keyv, a package with 600 million monthly downloads, then rapidly spread to flat-cache, file-entry-cache, and hundreds more.
The malware, built on the Mini Shai-Hulud framework, steals npm, GitHub, AWS, and CI credentials, plus crypto wallets and AI config files. Some compromised packages appear in 46% of all cloud environments. Researchers from Wiz, Aikido, Microsoft, and Socket are tracking the attack and have published indicators of compromise.
Source: CyberScoop
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo