Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages
2026-08-04T20:51:36Z•19b4962b7144afce8cbbd11056ce19899244c98b75e5686d966c66dca2443745
CI/CDGitHubJavaScriptShai-Huludcloud-securitycredential-theftmalwarenpmpackage-poisoningsoftware-supply-chainsupply-chain-attackworm
What happened
HackRead reports that the Shai-Hulud npm worm has returned, compromising the Keyv ecosystem and more than 1,280 npm packages. The campaign reportedly targets software supply chains and steals npm, GitHub, cloud, and CI/CD credentials in real time, creating significant downstream risk for developers and organizations consuming affected packages.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 19b4962b7144afce8cbbd11056ce19899244c98b75e5686d966c66dca2443745
- Enrichment time
- 2026-08-04T20:51:36Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.