August 2026 Summaries
1 posts from Cloudsmith
Filter
Month:
Year:
Post Summaries
Back to Blog
On August 4, 2026, a self-propagating worm initiated a supply-chain attack targeting npm packages, particularly keyv and cacheable, marking the event as keyv-shai-hulud. The attack involved the publication of 2,236 malicious versions across 444 legitimate packages, exploiting their deep integration into JavaScript dependency graphs. This attack was characterized by its rapid spread, facilitated by lifecycle scripts that executed harmful payloads to harvest credentials and propagate further. Organizations using npm v12 or later, which disables lifecycle scripts by default, have a degree of protection, while those on older versions or with scripts enabled remain vulnerable. To assess exposure, organizations must review lockfiles and package versions, ensuring they match updated community trackers, and confirm whether lifecycle scripts could execute in their environments. Cloudsmith offers a preventative measure by acting as an intermediary between public registries and developers, enforcing cooldown and malware policies that delay the availability of new versions and block those identified as malicious, thereby reducing the risk of such supply chain attacks.
Aug 04, 2026
1,074 words in the original blog post.