Keyv and friends compromised in active Shai-Hulud supply chain attack(aikido.dev)
246 points by cimi_ 1 day ago | 133 comments
tl;dr: Mini Shai-Hulud malware was injected into keyv and eight related npm packages on August 4, 2026 after an attacker compromised the maintainer's GitHub account...
HN Discussion:
  • npm install hooks should be deprecated or heavily restricted to prevent these attacks
  • The npm dependency ecosystem is fundamentally fragile and enables these supply chain attacks
  • Developers should adopt isolation/devcontainers and delayed package updates as defensive practices
  • GitHub should proactively detect and block Shai-Hulud exfiltration repos and compromised accounts
  • Seeking or sharing tools and resources to detect compromise in existing installations