logo

Massive supply-chain attack compromises 440 packages under four hours

ID: 8f3d8fe9-995f-5f24-a625-b06c9c3e42c9

STIX ID: report--8f3d8fe9-995f-5f24-a625-b06c9c3e42c9

Feed Name: CyberScoop

Threat Score
90/100

Date Published: 2026-08-04

Date Updated: 2026-08-05

Author: Matt Kapko

...
...

An attacker compromised a GitHub maintainer and rapidly deployed a Mini Shai-Hulud–based self-replicating worm that injected malicious code into hundreds of npm packages (initially keyv and related packages), ultimately affecting dozens of maintainers and over 860 packages with a combined ~2 billion monthly installs. The payload exfiltrates sensitive credentials (npm, GitHub, AWS, CI), AI-related config files, and crypto wallets; multiple security firms observed the same pattern and published IOCs, and attribution to a known actor (TeamPCP) is suspected but not fully confirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.