CYBERSECURITYTRACKER
TRACKING7,159 stories in this site build1,507 vulnerability news stories in this site build
Permanent story citation

Massive supply-chain attack compromises 440 packages under four hours

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3858

As cited

Copy frozen at (site build).

threat intel

Massive supply-chain attack compromises 440 packages under four hours

A threat actor compromised a GitHub maintainer account and deployed a self-replicating malware variant based on Mini Shai-Hulud across more than 440 npm packages in under four hours on Tuesday. The affected packages, including keyv and flat-cache, collectively receive over 2 billion monthly installs and are present in approximately 46 percent of cloud environments. The malware steals credentials, API tokens, and configuration data, though researchers have not observed new malicious activity since the initial wave.

Why it matters: Development teams and cloud operations relying on npm packages face immediate risk of credential theft and supply-chain compromise; audit systems for signs of the attack indicators published by Microsoft, Aikido, Socket, and Wiz, and rotate any exposed credentials.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Massive supply-chain attack compromises 440 packages under four hours

An attacker compromised a GitHub maintainer account and released a self-replicating worm based on the Mini Shai-Hulud malware, injecting malicious code into over 440 npm packages within four hours on August 4, 2026. The compromise spread to affect more than 860 packages with a combined 2 billion monthly installs, with some affected packages present in 46% of all cloud environments. The worm steals credentials (npm, GitHub, AWS, CI tokens), configuration files, and cryptocurrency wallets; researchers from multiple firms are monitoring the attack and publishing indicators of compromise.

Why it matters: Organizations using npm packages like keyv, flat-cache, or file-entry-cache (which account for over 155 million weekly downloads) must immediately scan for malicious activity, rotate exposed credentials, and review their supply-chain security posture given the attack's unprecedented scale and prevalence in cloud environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Massive supply-chain attack compromises 440 packages under four hours

An attacker compromised a GitHub maintainer account and released a self-replicating worm based on the Mini Shai-Hulud malware, injecting malicious code into over 440 npm packages within four hours on August 4, 2026. The compromise spread to affect more than 860 packages with a combined 2 billion monthly installs, with some affected packages present in 46% of all cloud environments. The worm steals credentials (npm, GitHub, AWS, CI tokens), configuration files, and cryptocurrency wallets; researchers from multiple firms are monitoring the attack and publishing indicators of compromise.

Why it matters: Organizations using npm packages like keyv, flat-cache, or file-entry-cache (which account for over 155 million weekly downloads) must immediately scan for malicious activity, rotate exposed credentials, and review their supply-chain security posture given the attack's unprecedented scale and prevalence in cloud environments.

VendorsMicrosoftGoogleAmazon Web ServicesGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary