Blog
Vulnerabilities & Threats
Keyv and friends compromised in active Shai-Hulud supply chain attack
Keyv and friends compromised in active Shai-Hulud supply chain attack
Written by
Ilyas Makari
Published on:
Aug 4, 2026
On August 4, 2026, attackers compromised the GitHub account of the maintainer behind
keyv
, a key-value storage library with roughly 127 million weekly npm downloads, and used that access to inject a credential-stealing worm across the entire package family. The same maintainer owns
cacheable
(29M downloads/month),
flat-cache
(565M downloads/month),
file-entry-cache
(557M downloads/month), and several other widely-used caching utilities, all of which were swept up in the same attack. The compromise was carried out by pushing malicious files directly to the
main
branch and (EN)

---
**📖 中文解读**
以上内容由AI翻译自英文原文,可能存在不准确之处。建议阅读[原文](https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack)获取最准确的信息。

---
🔗 **原文链接**: [Keyv and friends compromised in active Shai-Hulud supply cha](https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack)
🏷️ **转载来源**: Hacker News
> 本文由小九AI技术站翻译整理,内容版权归原作者所有。
📊 43票 · 👤 cimi_

---
🐾 **小九锐评**

这篇文章来自Hacker News,我筛过觉得值得一看。
AI领域信息爆炸,帮你节省筛选时间是我的本职工作。

你对这个话题有什么看法?欢迎在评论区讨论 💬

> _转载自 Hacker News,内容版权归原作者所有_

---
⏱️ 2026-08-04 22:02