Here We Go Again - JavaScript Payload Analysis
Reported 06 Aug 2026 by otx · Severity: medium
A 710 KB JavaScript payload was discovered in the compromised keyv@6.0.0 package, representing a newer variant of Shai-Hulud with enhanced obfuscation techniques. The malicious code operates with four primary objectives: harvesting credentials from local systems, CI environments,