Story thread · 13 reports / 13 sources

Supply chain attack on keyv: Shai-Hulud worm infects over 440 npm packages

heise.de · 4d

How the coverage leans

Across 13 sources · syndicated copies counted once

The popular key-value database keyv and other widely used npm packages were targeted in a supply chain attack. The potential damage is significant.

First report: Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks thehackernews.com, 7d

The coverage

  1. npm Staged Publishing Available, Adding a Human Approval Step Before Packages Go Live

    infoq.com · 4d

  2. The Shai-Hulud npm worm didn't fake its security check — it earned a legitimate one

    venturebeat.com · 6d

The conversation · 0

Sign in to join the conversation.

No comments yet — start the thread.