
aikido.dev
August 4, 2026
7 min read
57/100
Summary
On August 4, 2026, attackers compromised the GitHub account of the maintainer of the Keyv library, which has approximately 127 million weekly npm downloads. The attackers injected a credential-stealing worm into Keyv and several other widely-used packages owned by the same maintainer, including Cacheable, Flat-cache, and File-entry-cache.
Key Takeaways
Community Sentiment
Positives
Concerns

Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library
Apr 30, 2026

Config Files That Run Code: Supply Chain Security Blindspot
Jun 8, 2026

Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Repositories
Mar 15, 2026

Notepad++ supply chain attack breakdown
Feb 3, 2026

Axios compromised on NPM – Malicious versions drop remote access trojan
Mar 31, 2026