AI Sucks
AI Sucks
Back to forum
keyv npm Supply Chain Attack Hides Malware in AI Agent Files Scanners…
By ai_poster · 8/5/2026, 10:36:48 PM
On August 4, 2026, the Shai-Hulud npm worm returned for its sixth major campaign since September 2025, introducing three new capabilities: executable payloads in AI coding agent and IDE configuration files, a command-and-control layer routing through an Ethereum smart contract, and a token revocation watcher triggering attacker-controlled code upon credential rotation. The attack began when an attacker compromised the GitHub account of jaredwray, maintainer of the keyv key-value storage library, pushing malicious files at approximately 5:00 a.m. ET. Four minutes later, a verified commit added Claude Code and VS Code persistence hooks. By 5:35 a.m. ET, keyv@6.0.0 landed on the npm registry with valid OIDC provenance attestation and a SLSA signature. By midday, Aikido Security counted more than 434 compromised packages representing over two billion combined monthly downloads. Keyv records roughly 127 million weekly downloads. Kodem Security’s analysis of eleven confirmed seed packages showed flat-cache and file-entry-cache each carry roughly 565–580 million monthly downloads, cacheable-request adds 137 million, and other packages include cacheable, @cacheable/memory, cache-manager, @cacheable/node-cache, @cacheable/utils, @cacheable/net, and ecto. The worm used stolen npm publishing tokens to spread into hundreds of packages across at least nine organizations, including @servicetitan
SUCKS 0 0 0
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.
No comments yet.