Radio
Now Playing
Quickyla Radio โ€” Click to play
Open โ†’
3 min left
Back to News

The Shai-Hulud npm worm didn't fake its security check โ€” it earned a legitimate one

An attacker on Tuesday took over the GitHub account of the developer who maintains keyv , a small key-value storage library that npm serves roughly 127 million times a week. Within hours, poisoned veโ€ฆ

The Shai-Hulud npm worm didn't fake its security check โ€” it earned a legitimate one
VentureBeat โ€” 5 August 2026
Text:
38 0 0

An attacker on Tuesday took over the GitHub account of the developer who maintains keyv , a small key-value storage library that npm serves roughly 127 million times a week. Within hours, poisoned versions of keyv and its sibling caching packages were live on npm, carrying a credential-stealing worm. By midday, security firm Aikido counted at least 868 compromised packages across 1,381 versions, together carrying over two billion monthly installs, a total still climbing. JFrog independently traced the campaign across more than 400 packages and 1,700 poisoned versions. The part that should worry every security team is not the download count. It is the paperwork. The initial poisoned releases shipped with valid provenance signatures, the cryptographic attestation the industry built to prove a package came from where it claims. The worm did not forge that signature. It earned it, the way a legitimate release would. A day earlier, CrowdStrike published its 2026 Threat Hunting Report and pr

This report comes from VentureBeat. The story centres on The Shai-Hulud npm worm didn't fake its security check โ€” it earned a legitimate one. Full coverage and background context is available at the original source. Readers seeking more detail on this developing topic are encouraged to follow updates from VentureBeat and related outlets covering this beat.

Read Full Story at VentureBeat โ†’
Advertisement
React:
Sources
Sponsored

More to Read

7 Statesโ€™ Water Systems Hit by Cyberattacks Likely Tied to โ€ฆ
๐Ÿ’ป Technology
7 Statesโ€™ Water Systems Hit by Cyberattacks Likely Tied to Iran
Wired ยท 8 days ago
Hanwha Group and LG CNS tokenize trade receivables to enhanโ€ฆ
๐Ÿ’ป Technology
Hanwha Group and LG CNS tokenize trade receivables to enhance supply chain finance
CoinDesk ยท 14 days ago
Trump administration exempts SpaceX's Starlink from foreignโ€ฆ
๐Ÿ’ป Technology
Trump administration exempts SpaceX's Starlink from foreign router ban
Ars Technica ยท 13 days ago
Hereโ€™s the biggest news you missed this weekend
๐ŸŒ World News
Hereโ€™s the biggest news you missed this weekend
NBC News ยท 14 days ago
Ghana's community service bill: A fix for the prison crisis?
๐ŸŒ World News
Ghana's community service bill: A fix for the prison crisis?
DW World ยท 13 days ago
The Vatican still hasnโ€™t learned how to deal with abuse allโ€ฆ
๐Ÿ•Œ Religion & Faith
The Vatican still hasnโ€™t learned how to deal with abuse allegations
Crux Now ยท 14 days ago
Full view