Skip to content

nodejs

1 article on this topic

  • sicurezza
  • supply-chain

The worm that infected keyv: inside August's npm supply chain attack

On 4 August the GitHub account of the keyv maintainer was compromised, 127 million weekly downloads, and within two days a self-propagating worm poisoned over 1,300 package versions. You do not need to use keyv to be hit. What we checked across client pipelines.

, 2 min read

Have a project in mind?

Tell us what you need. We reply within one working day.

Articles: nodejs | SEM Devs