<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Massive Supply-Chain Attack Hits 440+ npm Packages in Under Four Hours

A GitHub account hijack spread malware across hundreds of npm packages, stealing credentials and crypto wallets. Rotate your tokens now.
Content Team

A single attacker hijacked a GitHub maintainer account on 4 August and unleashed self-replicating malware. More than 440 npm packages were compromised in under four hours, rising to over 860 in total, with more than 2 billion combined monthly installs.

The worm first hit keyv, a package with 600 million monthly downloads, then spread to flat-cache, file-entry-cache and hundreds more. Built on the Mini Shai-Hulud framework, it steals npm, GitHub, AWS and CI credentials, plus crypto wallets and AI config files.

Compromised packages appear in 46% of all cloud environments — up from around 28% in earlier Shai-Hulud campaigns. Researchers from Wiz, Aikido, Microsoft and Socket are tracking the attack and have published indicators of compromise.

Rotate npm, GitHub and AWS credentials immediately. Infected packages carry setup.mjs and Math_Symbol.js plus a preinstall hook, and the worm persists through VS Code and Claude Code config files — so removing the package alone won't evict it.

Source: CyberScoop

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo