#keyv
#ばばさん通信ダイジェスト 賛否関わらず話題になった/なりそうなものを共有しています。

なぜ悪性パッケージは届いてしまうのか、パッケージレジストリの対策の歴史から考える
https://blog.flatt.tech/entry/package_registry_history
なぜ悪性パッケージは届いてしまうのか、パッケージレジストリの対策の歴史から考える - GMO Flatt Security Blog
はじめに こんにちは。GMO Flatt Security株式会社 セキュリティエンジニアの井手(@st98_)です。 2026年に入ってから、パッケージレジストリを狙ったソフトウェアサプライチェーン攻撃のニュースが多数ありました。3月には axios や LiteLLM、4月には Bitwarden CLI、5月には TanStack、6月には Red Hat の namespace、そして8月には keyv と、名前を聞けば分かるような、あるいは(あまり意識されていないものの)広く使われているパッケージが立て続けに侵害されました。 そのたびに「lockfile を使う」「Trusted P…
blog.flatt.tech
September 21, 2026 at 5:56 AM
In Keyv, the boys and girls can be slutty!
September 10, 2026 at 10:42 PM
Mini Shai-Hulud's Latest Wave: 280 New Places It Hunts for Your Secrets
We have stopped counting the number of waves in the Shai-Hulud attack series, but this week has seen the rise of yet another iteration. This campaign started with the infection of the `keyv@6.0.0` npm package at 9:35 a.m. UTC on Aug. 4, 2026, and quickly spread across the ecosystem. The compromise chain reportedly affected more than 800 packages across thousands of versions, including: * `@cacheable/memory` * `ecto` * `cacheable-request` * `flat-cache` * and more The infection spread into the npm namespace of several well-known companies, including: * OneReach * Ornikar * Qlik * Picsart The last known malicious package was published at 12:27 a.m. UTC on Aug. 5, 2026. ## How the Mini Shai-Hulud infection chain works The infection mechanism used in this campaign is very familiar. It relies on an npm preinstall script, a mechanism that has been disabled by default since npm version 12. This script uses the same mechanism we have observed in similar campaigns: it downloads the Bun execution environment and uses it to load a heavily obfuscated JavaScript second-stage file named Math_Symbol.js. Payload file | SHA256 ---|--- setup.mjs | 54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668 Math_Symbol.js | 9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc Once deobfuscated, it is clear that this malware is part of the Mini Shai-Hulud family, whose source code was open-sourced by the Team PCP threat actor in May 2026. The main payload shares the key characteristics we know from this family of malware: * Aims for secrets, both locally and on remote systems. * Distinctively targets developers' endpoints and CI/CD runners. * Exfiltrates secrets to GitHub, including with a previously compromised key. * Persists through poisoning of Claude and VS Code configuration files. There are a few key novelties in this version worth noting. For example, the new version can download its command-and-control server address from the Ethereum blockchain. This mechanism is new to the Mini Shai-Hulud family, but the GlassWorm malware already used it in March 2026. The true evolution, however, lies in the expanded scope of the collection. ## 469 secret locations: how the collection scope expanded The Mini Shai-Hulud malware family is known for collecting secrets both locally and remotely. To do so, it uses distinct providers that target specific services: * The local file system * Local execution environment * CI/CD runner environments * AWS * Kubernetes * Vault The list of collectors has not changed with the new version. Instead, the scope of what each collector accesses has changed. The clearest example of this evolution is the file system provider, which is responsible for collecting secrets from developer machines. The open-source version of the malware collected secrets from a list of 189 hardcoded locations across Linux, Windows, and macOS environments. This new version raises the count to 469. | Mini-Shai Hulud | Latest version ---|---|--- Linux | 89 | 290 Windows | 12 | 50 macOS | 88 | 129 On Windows and macOS, the added paths mostly represent a catch-up with the previous version's Linux collector. On Linux, however, the changes are much more significant. First, the malware now tries to exploit elevated privileges to collect secrets from more locations. Previous versions only targeted files stored in the current user's home directory; the new one enumerates files across all users on the system, including administrative users. This means the impact of an execution with high privileges would be much more severe. The malware also expands the scope of its secret hunting by targeting configuration files for additional services and software, primarily AI agents, CI/CD software, cryptocurrency wallets, and cloud tools: the kinds of software most commonly found on developer machines. * **AI agents:** Cursor, OpenClaw, OpenAI Codex, OpenCode, Gemini, Hermes * **CI/CD:** ArgoCD, Jenkins, CircleCI * **Cloud:** Hetzner, Alibaba Cloud, Tencent Cloud * **Cryptocurrency:** Foundry, Brownie, Solana, Electrum The other collectors remain unchanged. They already collect most of the data they can access. ## Why npm supply chain attacks keep adapting Every new supply chain attack campaign comes with its own set of improvements. They sometimes arise in response to security hardening efforts and are sometimes purely functional. In recent months, we have seen threat actors adapt to the evolving security of the open-source ecosystem. The clearest example has been their adoption of OpenID Connect (OIDC) and attestations for package publication, a response to defenses introduced since the original Mini Shai-Hulud campaign in May 2026. This new iteration does not represent a huge technological leap, but it still improves on past campaigns. The increase in the scope of endpoint harvesting is not anecdotal; it shows threat actors are refining their understanding of secrets sprawl, especially on the endpoint. It is reasonable to expect future waves will further refine this part of the malware. With such a fast-moving threat, understanding where your credentials live has never been more important. That is why we, at GitGuardian, have been building our endpoint protection solution: so you know where your secrets live, which ones you can remove before an attack happens, and which ones you need to revoke once an infostealer campaign hits you. Don't let attackers know where to find your secrets better than you do.
dev.to
September 9, 2026 at 1:27 PM
A trojanized npm worm harvests cloud secrets and hides its C2 inside an Ethereum smart contract call. https://intel.threadlinqs.com/threat/TL-2026-2285 #ThreatIntel #ChainDrop #ShaiHulud #Bun
September 2, 2026 at 2:35 AM
The Shai-Hulud worm is back, targeting npm packages like keyv. It doesn't just steal tokens; it uses them to infect every other package a developer maintains. A stark reminder: your registry is your pipeline's weakest link.
Shai-Hulud Worm Targets npm and Poisons Pipelines
The Shai-Hulud worm is back, targeting npm packages like keyv. It doesn't just steal tokens; it uses them to infect every other package a developer maintains. A stark reminder: your registry is your p
www.alextech.ai
September 1, 2026 at 7:22 AM
www.youtube.com/watch?v=kEyv...
정기적으로 숫자송도 들어야한다
250927 KIRARA (키라라) - 숫자 @ 삼락생태공원 2025 부산국제록페스티벌 By MOLE
YouTube video by Mad Hatter영호의 인디가요
www.youtube.com
August 30, 2026 at 11:47 AM
Provenance proves who built the package. The attacker put the code in the repo and the real workflow signed it.

And agent config (.claude/settings.json) is code that runs with your credentials, and nobody reviews it.

Go grep your clones. Then: npm config set ignore-scripts true.
Inside the keyv npm Supply Chain Compromise | Snyk
The keyv npm compromise used preinstall malware, trusted provenance, and IDE hooks to target developer and CI credentials. Learn how to detect and respond.
snyk.io
August 29, 2026 at 9:59 AM
The npm worm from Aug 4 (keyv, 444 packages, ~2B monthly downloads) had valid provenance. Signed by GitHub Actions.

It also writes a Claude Code SessionStart hook and a VS Code folderOpen task into your repo. You don't install it. You open the folder.
August 29, 2026 at 9:59 AM
A new npm supply chain advisory affects Keyv and related package versions. Remove affected releases, rebuild systems that installed them, rotate exposed credentials, and review CI environments for unauthorized access.
August 26, 2026 at 1:14 PM
Shai-Hulud, 3e vague : keyv compromis, CHAINDROP, provenance npm valide, 800+ packages backdoorés.

📖 blog.gioria.org/fr/supply-ch...
📬 sgioria.substack.com/p/shai-hulud...

#DevSecOps #SupplyChain
August 25, 2026 at 9:45 AM
Michael Corleone said in The Godfather Part 3: "Just when I thought I was out, they pull me back in." Same for Mini Shai-Hulud. A new wave hit keyv & 800+ npm packages. #malware now scans 469 secret locations, including #AI agents & crypto. HT @GitGuardian. cybersec.gitguardian.com/s/mini-shai-...
Mini Shai-Hulud's Latest Wave: 280 New Places
A new Mini Shai-Hulud wave hit keyv and 800+ npm packages. The malware now scans 469 secret locations, including AI agents, crypto wallets, and CI/CD tools.
cybersec.gitguardian.com
August 20, 2026 at 4:14 PM
The keyv compromise on August 4 unfolded in under 30 minutes from malicious commit to release. The maintainer account was hijacked and signed bot commits spread the payload across branches. Watch for sudden unsigned commits on trusted repos
#IncidentResponse #npm #Security
August 20, 2026 at 3:09 AM
ChainDrop is the largest npm supply chain attack so far. Over 400 packages including keyv and cacheable were hit by a self-propagating worm named Mini Shai-Hulud that steals npm GitHub and cloud credentials then republishes infected patch versions automatically
#SupplyChainSecurity #npm #NodeJS
August 20, 2026 at 3:07 AM
The ChainDrop worm hit over 400 npm packages, including widely used ones like keyv. It steals CI credentials from GitHub Actions and republishes poisoned versions of dependencies it touches. Pin your versions, rotate secrets, and audit what changed in lockfiles this week. #npm #SupplyChain #Security
August 19, 2026 at 11:16 PM
El lockfile paró a keyv (5.6.0 → 6.0.0, major: ^5.6.0 lo rechaza) y no paró a flat-cache (6.1.23 → 6.1.24), cacheable (2.5.0 → 2.5.1) ni cache-manager (7.2.9 → 7.2.10), que fueron parches dentro del mismo major.

Lo que sí: minimum-release-age / cooldown. Vivieron ~2 h en el registro.
August 18, 2026 at 3:00 AM
Microsoft-onderzoek legt op grote schaal supply chain-aanval bloot met 444 geïnf

Een grootschalig beveiligingsonderzoek door Microsoft, dat de naam ChainDrop draagt en door andere onderzoekers Mini Shai-Hulud wordt genoemd, heeft geleid tot de ontdekking van 444 geïnfecteerde npm-pakketten....
Microsoft-onderzoek legt op grote schaal supply chain-aanval bloot met 444 geïnfecteerde npm-pakketten.
Een grootschalig beveiligingsonderzoek door Microsoft, dat de naam ChainDrop draagt en door andere onderzoekers Mini Shai-Hulud wordt genoemd, heeft geleid tot de ontdekking van 444 geïnfecteerde npm-pakketten. In totaal werden meer dan 1.300 kwaadaardige releases gepubliceerd. De aanval begon op 4 augustus 2026 met de compromittering van het GitHub-account achter de Keyv caching-bibliotheek, waardoor aanvallers controle kregen. Na deze initiële overname werden ook andere pakketten, waaronder cacheable, flat-cache en file-entry-cache, geïnfecteerd. Door gebruik te maken van gestolen inloggegevens konden de aanvallers gewijzigde releases publiceren en verdere publicatietoegang verkrijgen om...
newsfacts.info
August 17, 2026 at 7:00 AM
ChainDrop npm Worm Poisons 444 Packages Through GitHub Actions and Trusted Publishing
ChainDrop npm Worm Poisons 444 Packages Through GitHub Actions and Trusted Publishing
ChainDrop has made an npm package compromise a warning about developer machines. The self-propagating campaign poisoned 444 packages and more than 1,300 malicious releases after attackers took over the GitHub account tied to the Keyv caching library. The affected packages represented more than two billion monthly installs. The operation spread through stolen npm publishing tokens and legitimate release channels. It also moved beyond package installation: attackers added repository configuration that could run when a developer opened a project in VS Code or began a Claude Code session. A git clone and project open could therefore create exposure. Abby Kearns said in a report shared with Cyber Security News (CSN) that the distinction was the attacker’s choice to bypass the install step that supply-chain controls watch. Microsoft calls the campaign ChainDrop, while other researchers track it as Mini Shai-Hulud, following patterns seen in the  recent Mini Shai-Hulud campaign . The initial entry point has not been disclosed. Still, the incident shows how one compromised maintainer account can turn trusted publishing, automated workflows and developer tools into a distribution channel. It also asks whether engineering teams inspect repositories only as source code, rather than content that can instruct local tools to act. ChainDrop npm Worm The attack began on August 4 with the compromise of the GitHub account behind Keyv and packages including cacheable, flat-cache and file-entry-cache. Attackers used stolen credentials to publish altered releases, then harvested further publishing access to expand the infection. Projects tracking newest major versions were at particular risk, while older pinned majors were protected. The releases appeared trustworthy because they carried valid provenance attestations. Four steps from a stolen account (Source – Medium) They were published through a GitHub Actions workflow configured as an npm trusted publisher, so records showed that an approved identity performed the release. The problem was upstream: malicious source had entered the repository before the workflow ran, a lesson echoed by the  GitHub Actions workflow weakness  reported earlier this year. That distinction matters because provenance can confirm a build’s origin, but cannot guarantee that the computer, account or repository that produced it was clean. In this case, no signature was forged and no publishing pipeline was broken. The attackers abused access that the ecosystem was designed to trust. For maintainers, the response was complex and time consuming. The Keyv maintainer wiped affected machines, disabled GitHub Actions and trusted publishing, withdrew compromised versions, removed malicious branches and tags, and reset impacted branches. Teams should likewise revoke and rotate exposed credentials, review workflow permissions, and rebuild affected developer or CI environments from a known-clean state. Repository Files Become an Execution Path ChainDrop also placed two configuration files into reachable repositories across as many as 50 branches. One supplied a Claude Code SessionStart hook and the other defined a VS Code task to run when a folder opened. Each could launch a dropper from the other tool’s directory, allowing execution without an npm install or build. This approach falls outside the view of many dependency scanners. Those products commonly examine manifests and lockfiles to identify downloaded packages, not project settings that describe editor tasks or AI coding-tool behavior. The risk is similar to a  compromised automation action incident , where trusted development automation becomes the route to sensitive access. VS Code Workspace Trust and Claude Code trust checks can stop automatic activity in an untrusted project. But the danger increases after a developer has already marked a familiar checkout as trusted. Kearns advises teams to search every branch, not merely the main branch, for unexpected repository configuration and compare resolved versions with affected releases. Organizations should treat repository-supplied configuration as executable content and add those paths to review, monitoring and incident-response checks. They should inventory coding tools, examine files read at project open, restrict high-value tokens, and watch for  earlier npm package compromises  that may signal similar credential theft. ChainDrop shows that a safe dependency tree alone no longer guarantees a safe developer workspace. Indicators of compromise (IoCs):- Type Indicator Description File name .claude/settings.json Repository configuration file used to register a Claude Code SessionStart hook. File name .vscode/tasks.json Repository configuration file used to create a VS Code task triggered when a folder opens. Malicious package version keyv@6.0.0 Identified malicious release on the newest major package line. Malicious package version flat-cache@6.1.24 Identified malicious release associated with the ChainDrop campaign. Malicious package version file-entry-cache@11.1.6 Identified malicious release associated with the ChainDrop campaign. Malicious package version cacheable-request@13.0.20 Identified malicious release that could affect projects resolving that package version. Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Stop new phishing & malware before they compromise your business.  Integrate live intel from 15K SOCs around the world The post ChainDrop npm Worm Poisons 444 Packages Through GitHub Actions and Trusted Publishing appeared first on Cyber Security News .
cybersecuritynews.com
August 17, 2026 at 6:53 AM
The frontend may run in an untrusted browser. The system that delivers it often runs with authority.

npm install is execution. The 4 Aug keyv/cacheable compromise ran a preinstall hook, harvested CI credentials, and spread through stolen npm tokens.

If this frontend repository were compromised […]
Original post on mastodon.social
mastodon.social
August 15, 2026 at 8:38 PM