← Notícias
🤖 Ia Tech ⚠️ Média

The Shai-Hulud npm worm didn't fake its security check — it earned a legitimate one

An attacker on Tuesday took over the GitHub account of the developer who maintainskeyv, a small key-value storage library thatnpmserves roughly 127 million times a week. Within hours, poisoned versions of keyv and its sibling caching packages were live on npm, carrying a credential-stealing worm. By midday,security firm Aikidocounted at least 868 compromised packages across 1,381 versions, togethe

Fonte: VentureBeat AI Data: 2026-08-05 Cobertura: Ia Tech

An attacker on Tuesday took over the GitHub account of the developer who maintainskeyv, a small key-value storage library thatnpmserves roughly 127 million times a week. Within hours, poisoned versions of keyv and its sibling caching packages were live on npm, carrying a credential-stealing worm. By midday,security firm Aikidocounted at least 868 compromised packages across 1,381 versions, togethe

Fonte original
VentureBeat AI
Leia a matéria completa →
WhatsApp Twitter/X