
Shai-Hulud Returns: The npm Supply Chain Worm Turning Stolen Credentials Into New Infections
A self-propagating npm supply chain attack compromised keyv and 444+ packages with 2B+ monthly installs. Here's how Shai-Hulud works, why provenance checks aren't enough, and what security teams should do now.
Read more: Shai-Hulud Returns: The npm Supply Chain Worm Turning Stolen Credentials Into New Infections




