Live Cybersecurity News Ticker | Codekeeper

Massive Supply-Chain Attack Hits 860+ npm Packages in Under Four Hours

Written by Content Team | Aug 5, 2026, 8:52:11 PM

A single attacker hijacked a GitHub maintainer account early Tuesday and unleashed self-replicating malware that infected more than 860 npm packages with over 2 billion combined monthly installs — all within four hours. The worm first hit keyv, a package with 600 million monthly downloads, then rapidly spread to flat-cache, file-entry-cache, and hundreds more.

The malware, built on the Mini Shai-Hulud framework, steals npm, GitHub, AWS, and CI credentials, plus crypto wallets and AI config files. Some compromised packages appear in 46% of all cloud environments. Researchers from Wiz, Aikido, Microsoft, and Socket are tracking the attack and have published indicators of compromise.

Source: CyberScoop