The Shai-Hulud npm worm didn't fake its security check — it earned a legitimate one

AI Summary
An attacker gained control of the GitHub account of the developer behind the keyv library, leading to the release of malicious versions on npm. Over 868 compromised packages were identified, with the affected versions accumulating more than two billion monthly installs.
From the source
An attacker on Tuesday took over the GitHub account of the developer who maintains keyv, a small key-value storage library that npm serves roughly 127 million times a week. Within hours, poisoned versions of keyv and its sibling caching packages were live on npm, carrying a credential-stealing worm. By midday, security firm Aikido counted at least 868 compromised packages across 1,381 versions, together carrying over two billion monthly installs, a total still climbing. JFrog independently trace
The full text couldn't be loaded here (the source may require a subscription).
View original at VentureBeat AI