#keyv

3 posts · Last used 5d

Back to Timeline
Maik @maik@norden.social · 6d ago
Der GitHub-Account des Maintainers der Key-Value-Datenbank #keyv wurde kompromittiert Durch die Shai-Hulud-Lieferkettenattacke sind über 440 #npm-Pakete betroffen mit rund 2 Milliarden Downloads monatlich Der Schadcode startet automatisch bei Installation und sucht nach Zugangsdaten https://www.heise.de/news/Lieferketten-Angriff-auf-keyv-Shai-Hulud-Wurm-infiziert-mehr-als-440-npm-Pakete-11403078.html?seite=all
2
0
2
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Aug 04, 2026
#npm: A massive #SupplyChain attack has compromised 868+ npm packages carrying 2 billion+ monthly installs with a credential-stealing worm. It started with the compromise of the #GitHub account of the #keyv library with 127 million+ weekly downloads: 👇 https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack
1
2
4
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Aug 04, 2026
A new npm supply chain attack hijacked keyv and dozens of packages, spreading Shai-Hulud malware that steals cloud and CI/CD secrets. Rotate keys now. #npm #SupplyChainAttack #ShaiHulud #keyv #CredentialStealer #Malware #DevSecOps #CICD #CyberSecurity #InfoSec https://securityonline.info/npm-supply-chain-attack-keyv-shai-hulud/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0

You've seen all posts