Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages

2026-08-04T20:51:36Z19b4962b7144afce8cbbd11056ce19899244c98b75e5686d966c66dca2443745
CI/CDGitHubJavaScriptShai-Huludcloud-securitycredential-theftmalwarenpmpackage-poisoningsoftware-supply-chainsupply-chain-attackworm

What happened

HackRead reports that the Shai-Hulud npm worm has returned, compromising the Keyv ecosystem and more than 1,280 npm packages. The campaign reportedly targets software supply chains and steals npm, GitHub, cloud, and CI/CD credentials in real time, creating significant downstream risk for developers and organizations consuming affected packages.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
19b4962b7144afce8cbbd11056ce19899244c98b75e5686d966c66dca2443745
Enrichment time
2026-08-04T20:51:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.