In brief: The Shai-Hulud worm has spread via the npm library keyv and other packages, now affecting more than 440 npm packages in the JavaScript ecosystem.
The popular key-value database keyv and other widely used npm packages have become the target of a software supply chain attack. The worm, known as Shai-Hulud, has spread via infected packages and, according to current findings, affects more than 440 npm packages.
Security researchers have identified a supply chain attack on the npm ecosystem in which the popular package keyv, along with numerous other widely used npm packages, was compromised. The attack is referred to as the Shai-Hulud worm and has propagated autonomously via infected dependencies. According to current knowledge, more than 440 npm packages are affected.
This incident is relevant for CISOs because npm packages are deeply embedded in build and CI/CD pipelines and can infiltrate production code unchecked via transitive dependencies. A worm-like propagation pattern increases the risk that organizations are affected even if they do not use keyv or the originally infected packages directly, but only indirectly through other libraries. The potential damage ranges from data exfiltration to the compromise of development environments and deployment processes.
Security officers should promptly check their Software Bill of Materials (SBOM) for the use of keyv and related packages, identify affected versions, and review dependency trees for suspicious updates. It is also advisable to review CI/CD logs for unusual package installations during the relevant time period and to suspend automatic updates for Node.js dependencies until the scope of the compromise has been fully clarified.
Source: www.heise.de · Published August 7, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.