The Shai-Hulud npm Worm of August 4, 2026: Full Breakdown of the Attack That Poisoned 1,280+ Packages
From the member
gbtilabsOn August 4, 2026, attackers reportedly compromised the GitHub account of the maintainer behind keyv, flat-cache, and related packages, then pushed a self-propagating npm worm that spread to more than 1,280 packages with roughly 2 billion monthly downloads. The malware ran through a preinstall script, stole credentials such as npm tokens, GitHub tokens, cloud keys, SSH keys, and other secrets, then used those credentials to infect additional packages across unrelated organizations. Any system that installed an affected version should be treated as fully compromised: pin or roll back dependencies, remove persistence mechanisms, rotate all exposed credentials, clear caches, and rebuild systems from scratch.

0 Comments
No comments yet. Be the first. Members comment from the GBTI local client, where comments are submitted as pull requests and auto-published for paid members.
Become a memberMembers write comments from the GBTI client or browser extension. Become a member to join the conversation.
You are signed in as a member. .