New npm Worm Hits 400+ Packages Including Keyv, Cachable
ID: 2cb939d2-268f-5ab7-b3d1-09cb9afd4afa
STIX ID: report--2cb939d2-268f-5ab7-b3d1-09cb9afd4afa
Feed Name: OpenSourceMalware Blog
Date Published: 2026-08-05
Date Updated: 2026-08-06
Author: c0a15726-c5b1-4b0d-85e6-fe15553df9e2
This report describes an active npm-based worm (Mini Shai-Hulud family) that has compromised 400+ packages and 2,000+ malicious versions to steal a wide range of developer and cloud credentials (GitHub, npm, AWS, Vault, Kubernetes, Azure, GCP, Terraform, Docker, Slack, etc.), exfiltrate data via a dynamic C2 and public GitHub repositories, and propagate by publishing poisoned npm releases and injecting GitHub workflows and commits; it includes technical analysis, SHA-256 hashes, IOCs, and containment/response guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
