Themata.AI
Themata.AI

Popular tags:

#developer-tools#ai-agents#llms#claude#ai-ethics#code-generation#ai-safety#openai#anthropic#discussion

AI is changing the world. Don't stay behind. Clear summaries, community insight, delivered without the noise. Subscribe to never miss a beat.

© 2026 Themata.AI • All Rights Reserved

Archive

|

Topics

|

Privacy

|

Cookies

|

Contact
🕒 Latest🔥 Top

Filtering by tag:

npmClear
Keyv and friends compromised in npm supply chain attack
npmsupply-chain-attackdeveloper-toolscybersecurity
News

Keyv and friends compromised in active Shai-Hulud supply chain attack

On August 4, 2026, attackers compromised the GitHub account of the maintainer of the Keyv library, which has approximately 127 million weekly npm downloads. The attackers injected a credential-stealing worm into Keyv and several other widely-used packages owned by the same maintainer, including Cacheable, Flat-cache, and File-entry-cache.

aikido.dev

🔥🔥🔥🔥🔥

7 min

8/4/2026

Axios compromised on NPM – Malicious versions drop remote access trojan

Two malicious versions of the axios HTTP client library, axios@1.14.1 and axios@0.30.4, were published to npm using compromised credentials of a lead maintainer. The attacker altered the maintainer's email to a ProtonMail address and manually published the malicious packages, which included a remote access Trojan.

stepsecurity.io

🔥🔥🔥🔥🔥

17 min

3/31/2026

Keyv and friends compromised in active Shai-Hulud supply chain attack

On August 4, 2026, attackers compromised the GitHub account of the maintainer of the Keyv library, which has approximately 127 million weekly npm downloads. The attackers injected a credential-stealing worm into Keyv and several other widely-used packages owned by the same maintainer, including Cacheable, Flat-cache, and File-entry-cache.

aikido.dev

🔥🔥🔥🔥🔥

7 min

8/4/2026

Axios compromised on NPM – Malicious versions drop remote access trojan

Two malicious versions of the axios HTTP client library, axios@1.14.1 and axios@0.30.4, were published to npm using compromised credentials of a lead maintainer. The attacker altered the maintainer's email to a ProtonMail address and manually published the malicious packages, which included a remote access Trojan.

stepsecurity.io

🔥🔥🔥🔥🔥

17 min

3/31/2026

Keyv and friends compromised in active Shai-Hulud supply chain attack

On August 4, 2026, attackers compromised the GitHub account of the maintainer of the Keyv library, which has approximately 127 million weekly npm downloads. The attackers injected a credential-stealing worm into Keyv and several other widely-used packages owned by the same maintainer, including Cacheable, Flat-cache, and File-entry-cache.

aikido.dev

🔥🔥🔥🔥🔥

7 min

8/4/2026

Axios compromised on NPM – Malicious versions drop remote access trojan

Two malicious versions of the axios HTTP client library, axios@1.14.1 and axios@0.30.4, were published to npm using compromised credentials of a lead maintainer. The attacker altered the maintainer's email to a ProtonMail address and manually published the malicious packages, which included a remote access Trojan.

stepsecurity.io

🔥🔥🔥🔥🔥

17 min

3/31/2026

No more articles to load