DIFF.BLOG
New Following Discover Jobs
More
Top Writers Suggest a blog Upvotes plugin
Report bug Contact About
Sign up
Topics
Follow your own topics →
Menu
New Following Discover Jobs Top Writers
More
Suggest a blog Upvotes plugin Report bug Contact About
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS

Aikido Security tracks Shai-Hulud npm package infection surge

1 · Developer Tech · Aug. 4, 2026, 2:53 p.m.
Build & Ship CI/CD & Release Engineering Containers & Kubernetes Cybersecurity & Development npm github Security malware
Summary
Aikido Security reports a surge in infections of the Keyv npm package due to a supply chain attack that compromised the maintainer's GitHub account, pushing malicious code. This incident highlights ongoing vulnerabilities in the npm ecosystem.
Read full post on www.developer-tech.com →
MORE POSTS LIKE THIS
GitLab discovers widespread npm supply chain attack
GitLabBlog · Nov 24, 2025
Cybersecurity npm
github: Restricting npm bypass-2FA granular access tokens
Sujith Quintelier · Aug 1, 2026
npm github
PolinRider supply chain attack expands to Packagist ecosystem
Developer Tech · Jul 2, 2026
Architecture & Methods Blockchain
The Axios supply chain attack used individually targeted social engineering
simonw · Apr 3, 2026
Open Source packaging
Weekly Wire #3: Agents on the Loose
andreafortuna · Aug 2, 2026
Security Weekly Wire
The Good, the Bad and the Ugly in Cybersecurity – Week 29
Sentinelone · Jul 17, 2026
Company Cyber
Discover more posts →
AUTHOR
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub Continue with Google