Keyv and friends compromised in active Shai-Hulud supply chain attack
ID: 1c1828f1-1aaa-5879-9306-56545d7f2bd6
STIX ID: report--1c1828f1-1aaa-5879-9306-56545d7f2bd6
Feed Name: Aikido Security's Blog
On 2026-08-04 attackers compromised the GitHub account of the maintainer for keyv and multiple widely used caching libraries, pushed malicious files to main, and released poisoned npm packages signed via GitHub Actions; the supply‑chain worm added a preinstall dropper (setup.mjs) that downloads Bun to execute an obfuscated credential‑stealer (Math_Symbol.js) which harvests npm/GitHub/AWS/Vault secrets, exfiltrates them to a public GitHub repo, and propagates to other packages — at least 868 packages (1,381 versions) and over 2 billion monthly installs were affected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
