Supply chain attack on keyv: Shai-Hulud worm infects over 440 npm packages
TL;DR
AI-generated
A supply chain attack has compromised over 440 npm packages, including the popular database keyv. Attackers used a variant of the Shai-Hulud worm to steal credentials from affected systems and upload them to controlled GitHub repositories.
Source: heise.de
Same event
- Access Data at Risk: Worm Hijacks NPM Packages with Billions of Downloads
- Supply chain attack on keyv: Shai-Hulud worm infects over 440 npm packages
- After Supply Chain Attack: Huge Data Leak Affects Countless Large Corporations
Discussion
Log in to join the discussion.
No comments yet. Be the first!