Major Shai Hulud campaign strikes npm again, affecting keyv and 400+ packages

Reported 06 Aug 2026 by otx · Severity: medium

A sophisticated supply-chain attack campaign named Shai-Hulud has compromised over 400 npm packages across 1700+ versions, beginning with keyv and cacheable libraries. The malware operates as a self-propagating worm that collects credentials from local filesystems, CI/CD environm