Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Malicious macOS ClickFix Domains Hide Atomic Stealer Attacks via Browser Fingerprinting
August 6, 2026
CISA Warns of Critical TeamCity RCE Vulnerability, CVE-2023-42793, Actively Exploited
August 6, 2026
Apple iCloud Private Relay WebKit Flaws Expose User IP Addresses
August 6, 2026
Home/Threats/Critical npm Supply Chain Attack Compromises Keyv Library, Hundreds of Packages
Threats

Critical npm Supply Chain Attack Compromises Keyv Library, Hundreds of Packages

Key Takeaways A new npm supply chain attack, dubbed “Mini Shai-Hulud,” began with the compromise of the Keyv library maintainer account. Attackers leveraged stolen publishing tokens to...

Sarah simpson
Sarah simpson
August 6, 2026 3 Min Read
4 0

Key Takeaways

  • A new npm supply chain attack, dubbed “Mini Shai-Hulud,” began with the compromise of the Keyv library maintainer account.
  • Attackers leveraged stolen publishing tokens to inject malicious code into hundreds of legitimate npm packages, turning them into credential theft vectors.
  • The malware is designed to self-propagate by stealing additional publishing tokens from infected systems, creating a chain reaction across the npm registry.
  • Affected organizations must remove compromised packages, rotate credentials across all impacted systems (npm, code-hosting, cloud, CI), and implement stronger supply chain security measures.
  • Microsoft and Socket researchers identified 2,234 affected package artifacts across 444 unique packages.

A recent and significant npm supply chain attack has transformed trusted software packages into a pipeline for credential theft. This sophisticated campaign originated from the compromise of the maintainer account for the widely utilized Keyv library. Attackers subsequently exploited this access to disseminate malicious releases across an expanding array of projects, as detailed in a comprehensive report .

The significance of this incident stems from the widespread and automated nature of npm package installations within modern development and build workflows. A compromised dependency can effortlessly infiltrate developer machines, production servers, and CI/CD pipelines without any human interaction with suspicious links or attachments.

Researchers from Microsoft and Socket have identified this malicious activity as an active “Mini Shai-Hulud” campaign. This self-propagating malware operation is specifically engineered to steal access tokens and subsequently reuse them for further compromises. Both firms shared reports with Cyber Security News (CSN), indicating that the attackers were leveraging multiple stolen publishing tokens to fuel the expansion of the attack.

The scale of the compromise rapidly escalated. Socket reported an alarming 2,234 affected package artifacts across 444 distinct packages while the malicious activity was still ongoing. This demonstrates the profound downstream risk a single compromised maintainer account can pose to countless development teams globally who rely on open-source components. Further details on the campaign were highlighted in a report available here.

New npm Supply Chain Attack Began

The attack vector originated with the compromise of a trusted account linked to Keyv, a widely adopted key-value storage library. With publishing privileges secured, the attackers were able to distribute modified packages that appeared to be legitimate updates, seamlessly integrated into the standard npm installation process.

This initial breach provided the campaign with a broad reach. Keyv’s substantial weekly download volume meant that its compromise placed a critical dependency at the core of a larger security incident. This event has reignited concerns regarding “Keyv package compromise details,” where established update channels become the conduit for malicious payloads.

The malicious releases incorporated an install-time instruction designed to initiate the attack before a developer could even interact with the package. As Socket reported on August 4, 2026, the malware does not simply infect a single machine. Instead, it actively searches for credentials that enable it to publish further altered releases from other maintainers, thereby creating a cascading effect across the entire registry. More information is available <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/f2dc9e39-097d-455a-bdfa-23a02b629dbf/New-npm-Supply-Chain-Attack-Began-with-the-Keyv-Library-Compromised-Hundreds-of-Popular-Packages_1.pdf?AWSAccessKeyId=ASIA2F3EMEYEWVOZA6UH&Signature=IR6VTaf5cZVaiFbAWJhJ1HyL6Bg%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEG0aCXVzLWVhc3QtMSJGMEQCIDWcqGOQUV%2BouxnPym65E0WGa6uVBpC1CpQ9%2FVEFJtX4AiAIuDJAD8u6bn12T0uMjWj9%2BKUANbM0sYvtni58bpDf%2BSrzBAg2EAEaDDY5OTc1MzMwOTcwNSIMpSVvhJ7%2FDGef%2FL80KtAEsPboYbHTehQU22mS%2Fflm0IR67V4ZAvjb9uS%2FfUSlpazhQnjhNNwn3%2FP86k310y%2F7zEmNwDzYS66mMXbjArNJumwe2skNurlsWmw2h0gtArd4ki4Y6fQzNpcgWyb55019YU5b1U%2FOs%2BtGUPyu2XCYeBu185VP%2B8hTHzOljHeADPwYmUvOOZNgDbMwjmkLZjosL7s3J01MNOYmuJ%2BEgnfVQGke1glTkhPn1wkOAZq8FPphyB4BdpcynhVVLWA07S6Kao0p4LnlprEfQMumOOnqKajbNZJU9Kqj0BXIBEsXFOTR06jnsl1lMsrVEnFUysbOuAkzowZA3xYnj7VqRaN3OXCKULWog7EeJrB7Jng0bBUXcrkb4iOiOROMB0Fq%2BcrQ8%2FvXgpGVIbdlcaZF

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Attackers Exploit Microsoft, Zoom Flaws to Target Government Agencies

Next Post

Apple iCloud Private Relay WebKit Flaws Expose User IP Addresses

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Google Blogger Bug Locked Legitimate Sites, Mistaking Them for Malware
August 6, 2026
Cisco Patches Critical SD-WAN Vulnerabilities, Update Now
August 6, 2026
Poison Claude Sells AI Tokens From Fake Accounts and Free Credits
August 5, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us