Aikido Security says an npm supply chain attack has infected Keyv packages with a variant of the credential-stealing Shai-Hulud malware. The security firm reports that attackers have compromised the ...
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...