Major Shai Hulud campaign strikes npm again, affecting keyv and 400+ packages
Reported 06 Aug 2026 by otx · Severity: medium
A sophisticated supply-chain attack campaign named Shai-Hulud has compromised over 400 npm packages across 1700+ versions, beginning with keyv and cacheable libraries. The malware operates as a self-propagating worm that collects credentials from local filesystems, CI/CD environm