Over 400 npm Packages Infected by Credential-Stealing Worm
Article Content
- •Over 400 npm packages have been compromised by a self-replicating worm.
- •The malware steals developer credentials and propagates through malicious package updates.
- •Key affected packages include keyv, flat-cache, and cache-manager.
A self-replicating worm, identified as a variant of Mini Shai-Hulud, has compromised over 400 npm packages from various unrelated publishers. The malware is designed to steal developer credentials and propagate itself by publishing malicious versions of the affected libraries. Notable packages impacted include keyv, flat-cache, and cache-manager. The worm exploits vulnerabilities in the npm ecosystem to facilitate its spread. Developers are urged to review their dependencies and take necessary precautions. The attack highlights significant risks within the software supply chain. No specific CVEs have been reported yet, but the scale of the infection raises alarms.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Mini Shai-Hulud in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
UAC-0099 Uses GuardBreaker to Evade AI Malware Detection Russian-linked hackers from the group UAC-0099 have developed a new technique called GuardBreaker to evade AI-assisted malware analysis. This method involves embedding a nuclear weapon prompt in malicious VBS scripts, which distracts AI systems from analyzing the actual malware code. The script is designed to download…
Critical OVERPASS Vulnerability in SAP Kernel Requires Immediate Action On September 8, 2026, SAP released security updates addressing 20 vulnerabilities, including a critical memory corruption flaw tracked as CVE-2026-44756, named OVERPASS. This vulnerability allows unauthenticated attackers to execute arbitrary commands on vulnerable SAP systems, leading to full compromise of business…