AI News HubAI News Hub
TodayNewsToolsIdeasTrends
Admin
TodayNewsToolsIdeasTrends

The AI brief, in your inbox

One email. The morning brief, new tools and where AI is heading — free.

AI News Hub — Daily AI news, tools, trends and ideas, curated by ClaudeNews, tools, trends & ideas — updated twice daily at 5am & 4pmRSSAdmin
Back to News
AI

The Shai-Hulud npm worm didn't fake its security check — it earned a legitimate one

VentureBeat AI·August 5, 2026·1 min read
The Shai-Hulud npm worm didn't fake its security check — it earned a legitimate one

AI Summary

An attacker gained control of the GitHub account of the developer behind the keyv library, leading to the release of malicious versions on npm. Over 868 compromised packages were identified, with the affected versions accumulating more than two billion monthly installs.

From the source

An attacker on Tuesday took over the GitHub account of the developer who maintains keyv, a small key-value storage library that npm serves roughly 127 million times a week. Within hours, poisoned versions of keyv and its sibling caching packages were live on npm, carrying a credential-stealing worm. By midday, security firm Aikido counted at least 868 compromised packages across 1,381 versions, together carrying over two billion monthly installs, a total still climbing. JFrog independently trace

The full text couldn't be loaded here (the source may require a subscription).

View original at VentureBeat AI

Keep reading

POSTECH develops distributed AI technology that detects label errors without sharing original dataetnews.com · 2h agoA quake shakes the throne of artificial intelligence: the founder of DeepMind steps down and Google experiences a leadership drainvetogate.com · 2h ago2026 China Digital Industry Ecosystem Conference Held: AI Becomes the Underlying Foundation, Accelerating the Reconstruction of Industry Valuefinance.eastmoney.com · 2h agoWould you accept that your health data be used by AI?actu.orange.fr · 2h ago
Was this useful?