August 4, 2026

npm install? More like npm in trouble

Keyv and friends compromised in active Shai-Hulud supply chain attack

A tiny code tool turned into a mega break-in, and commenters are absolutely fuming

TLDR: Attackers slipped secret-stealing malware into hugely popular software packages, turning ordinary installs into a mass credential grab. The community reaction is a mix of panic and rage: some blame GitHub for missing obvious warning signs, while others want install-time scripts banned altogether.

The real chaos here isn’t just that a hugely popular coding tool family got hijacked — it’s that the community is now having a full-on blame Olympics about how this was even allowed to happen. Attackers took over a maintainer’s account, slipped secret-stealing code into packages used all over the internet, and pushed it out so fast it looked officially blessed. The result: hundreds of poisoned packages, more than 2 billion monthly installs in the blast radius, and a lot of developers suddenly side-eyeing every install button like it’s haunted.

And wow, the comments came in hot. One camp is furious at GitHub, basically asking: how is there not a basic alarm for obviously shady uploads? Another group wants to go even further, calling the automatic “run code during install” feature a menace that should be killed off entirely. That take got plenty of support, because to non-experts the scandal boils down to this: people installed software, and the software started snooping around for passwords, cloud keys, and publishing tokens before anyone noticed.

But not everyone was buying the headline math. One skeptical commenter accused the write-up of clickbaiting with giant install numbers, arguing that many of those installs happen on automated systems, not actual laptops full of juicy secrets. Others mixed panic with gallows humor, roasting security tooling websites for melting browsers while the ecosystem melts down. In short: terror, finger-pointing, snark — and a lot of “burn it all down and redesign this stuff” energy.

Key Points

  • Attackers compromised the GitHub account of the maintainer behind keyv and related npm packages on August 4, 2026, and published malware-tainted releases.
  • The malicious releases were pushed from the main branch and published to npm with valid provenance signed by GitHub Actions.
  • Affected packages were modified to include setup.mjs, Math_Symbol.js, and a preinstall hook that executed automatically during npm install.
  • The payload stole npm, GitHub, AWS, and Kubernetes credentials, encrypted the data, and exfiltrated it to a public GitHub repository while also attempting worm-like propagation.
  • The article's update says at least 868 packages across 1,381 versions had been compromised, totaling more than 2 billion monthly installs.

Hottest takes

"an intern can slop the 80/20 together in a day" — avaer
"It’s time pre-install / post-install hooks were killed off" — xnorswap
"This is such lazy or click baiting writing" — vlovich123
Made with <3 by @siedrix and @shesho from CDMX. Powered by Forge&Hive.
Keyv and friends compromised in active Shai-Hulud supply chain attack - Weaving News | Weaving News