A Keyv-linked npm worm poisoned 353 versions across 79 package names, stealing developer and CI credentials while repository ...
A hijacked GitHub account let the Shai-Hulud worm pass npm's trust check, spreading through packages with 2 billion monthly ...
A Mini Shai-Hulud worm spread through more than 400 npm packages, stealing npm, GitHub, cloud, and CI/CD credentials.
Another Shai-Hulud variant hits npm packages, worming its way into hundreds of packages.
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
Security researchers have warned of a major new Shai-Hulud-based campaign which has already compromised more than 430 ...
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly ...
A self-spreading worm poisoned hundreds of npm packages in hours, slipped past provenance checks, hid its controls on Ethereum, and hunted AI-tool keys.
More than 400 NPM packages have been infected with the Mini Shai-Hulud worm in the ChainDrop supply chain attack.
The Shai Hulud variant’s blast radius includes several highly popular packages thus far.. Security teams are urged to perform ...
For the third time in just a few weeks, experts are warning of a significant threat to the open source npm ecosystem, after discovering a first-of-its-kind worm designed to steal secrets. On Monday, ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results