Massive Supply-Chain Attack Hits 440+ npm Packages in Under Four Hours
Want more insights like this?
A single attacker hijacked a GitHub maintainer account on 4 August and unleashed self-replicating malware. More than 440 npm packages were compromised in under four hours, rising to over 860 in total, with more than 2 billion combined monthly installs.
The worm first hit keyv, a package with 600 million monthly downloads, then spread to flat-cache, file-entry-cache and hundreds more. Built on the Mini Shai-Hulud framework, it steals npm, GitHub, AWS and CI credentials, plus crypto wallets and AI config files.
Compromised packages appear in 46% of all cloud environments — up from around 28% in earlier Shai-Hulud campaigns. Researchers from Wiz, Aikido, Microsoft and Socket are tracking the attack and have published indicators of compromise.
Rotate npm, GitHub and AWS credentials immediately. Infected packages carry setup.mjs and Math_Symbol.js plus a preinstall hook, and the worm persists through VS Code and Claude Code config files — so removing the package alone won't evict it.
Source: CyberScoop