Shai-Hulud Strikes Back: Keyv, Cacheable & 800+ npm Packages Hijacked in Massive Worm Attack
dev.to·
A massive supply chain worm attack has struck the Node.js ecosystem, compromising over 800 npm packages including widely used libraries like Keyv and Cacheable. Worm-style automated attacks propagate rapidly across interdependent modules by leveraging compromised maintainer accounts or tokens, injecting malicious payloads deep into standard dependency trees. For developers and software engineers, this outbreak highlights the ongoing vulnerabilities inherent in modern JavaScript dependency chains where nested transitive packages can expose production systems to remote code execution. Mitigating these ecosystem threats requires immediate lockfile reviews, automated dependency auditing, integrity checks, and stricter access controls across deployment pipelines to prevent rogue packages from deploying silently.