ThreatCluster

Over 400 npm Packages Infected by Credential-Stealing Worm

First seen 6 Aug 2026, 07:21 UTC Ciberseguridadlatam 92% similarity 66

Article Content

Browse articles
ThreatCluster

A self-replicating worm, identified as a variant of Mini Shai-Hulud, has compromised over 400 npm packages from various unrelated publishers. The malware is designed to steal developer credentials and propagate itself by publishing malicious versions of the affected libraries. Notable packages impacted include keyv, flat-cache, and cache-manager. The worm exploits vulnerabilities in the npm ecosystem to facilitate its spread. Developers are urged to review their dependencies and take necessary precautions. The attack highlights significant risks within the software supply chain. No specific CVEs have been reported yet, but the scale of the infection raises alarms.

Key Points: • Over 400 npm packages have been compromised by a self-replicating worm. • The malware steals developer credentials and propagates through malicious package updates. • Key affected packages include keyv, flat-cache, and cache-manager.

ThreatCluster AI How this analysis works

Timeline

2026-08-06
Worm identified in npm packages
A variant of Mini Shai-Hulud was found to infect over 400 npm packages, affecting multiple unrelated publishers.
Ciberseguridadlatam
2026-08-06
Malware propagation method detailed
The worm propagates by publishing malicious versions of the compromised libraries, targeting developers' credentials.
Ciberseguridadlatam

Community

Browse all →

Tracked Entities in This Story