Dossier
Keyv
Coverage of Keyv in the Nexus archive.
- Massive supply-chain attack compromises 440 packages under four hours
An attacker compromised a GitHub maintainer account and injected malicious code into over 440 npm packages within four hours using a self-replicating worm based on the Mini Shai-Hulud repository. The malware targeted credentials and sensitive data, affecting packages like keyv, flat-cache, and file-entry-cache, which are present in 46% of cloud environments.