Worm Compromises npm's keyv Package and Eight Other Organisations
A worm spread an identical credential stealer through nine unrelated npm organisations within roughly 30 minutes, hitting keyv and cacheable packages among others. Affected packages include authentication libraries, and a dead-man switch fires when stolen GitHub tokens are revoked, making credential rotation risky without prior cleanup.
Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.