Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages

https://hackread.com/wp-content/uploads/2026/08/shai-hulud-npm-worm-poisoning-1280-packages.jpg

A fast-moving software supply-chain attack has compromised Keyv and hundreds of other npm packages, exposing developer workstations and continuous integration systems to credential-stealing malware. Aikido Security identified the malware as a Shai-Hulud variant, following earlier campaigns reported by Hackread.com in 2025.

Antivirus& Malware

Aikido traced the initial attack to the GitHub account of developer Jared Wray, maintainer of Keyv, a key-value storage library receiving roughly 127 million weekly npm downloads. Attackers pushed malicious files directly to the main branch and used the legitimate GitHub Actions release process to publish Keyv version 6.0.0.

Because the poisoned release passed through the project’s normal publishing workflow, it carried valid provenance information on npm. The signature verified where the package was built, but not whether the source code entering that process was safe.

How the Attack Works

The first poisoned releases identified in Wray’s package family included Keyv, flat-cache, file-entry-cache, cacheable-request, cacheable, cache-manager, @cacheable/memory,...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE

Read more