sicurezzasupply-chainnodejs
The worm that infected keyv: inside August's npm supply chain attack
On 4 August the GitHub account of the keyv maintainer was compromised, 127 million weekly downloads, and within two days a self-propagating worm poisoned over 1,300 package versions. You do not need to use keyv to be hit. What we checked across client pipelines.
2 min read