A single attacker hijacked a GitHub maintainer account early Tuesday and unleashed self-replicating malware that infected more than 860 npm packages with over 2 billion combined monthly installs — all within four hours. The worm first hit keyv, a package with 600 million monthly downloads, then rapidly spread to flat-cache, file-entry-cache, and hundreds more.
The malware, built on the Mini Shai-Hulud framework, steals npm, GitHub, AWS, and CI credentials, plus crypto wallets and AI config files. Some compromised packages appear in 46% of all cloud environments. Researchers from Wiz, Aikido, Microsoft, and Socket are tracking the attack and have published indicators of compromise.
Source: CyberScoop