2026年8月4日,攻击者入侵了keyv库维护者的GitHub账户,并在包括keyv、flat-cache、file-entry-cache等多个npm包中注入恶意代码[1]。这起被称为"Shai-Hulud"的供应链攻击至少影响了434个npm包(1381个版本),涉及超过20亿的月安装量[1]。
恶意软件通过setup.mjs和高度混淆的Math_Symbol.js文件实现,其中Math_Symbol.js文件大小达728KB[1]。攻击代码会下载Bun JavaScript运行时并执行真正的攻击负载,能够窃取npm令牌、GitHub令牌、AWS凭证、Kubernetes密钥、HashiCorp Vault令牌以及Stripe和Slack令牌等多种敏感信息[1]。盗取的数据通过RSA加密后,被发送至公开GitHub仓库(其描述包含"Shai-Hulud: Here We Go Again")和外部域名https://npm-cache[.]com:443/router进行外泄[1]。
受影响的核心包包括月下载量达604百万次的keyv 6.0.0、580百万次的flat-cache 6.1.24和571百万次的file-entry-cache 11.1.6[1]。
Attackers breached the GitHub account of the Keyv library maintainer on August 4, 2026, injecting credential-stealing malware into multiple npm packages [1]. The compromise affected at least 434 packages across 1,381 versions, with combined monthly installation volumes exceeding 2 billion [1]. Among the most heavily downloaded compromised packages were Keyv 6.0.0 (604 million monthly downloads), flat-cache 6.1.24 (580 million monthly downloads), and file-entry-cache 11.1.6 (571 million monthly downloads) [1].
The malicious payload was delivered through setup.mjs files that downloaded a Bun JavaScript runtime to execute the actual attack code [1]. A highly obfuscated Math_Symbol.js file, measuring 728 KB, was also part of the infection mechanism [1]. The worm targeted sensitive credentials including npm tokens, GitHub tokens, AWS credentials, Kubernetes secrets, HashiCorp Vault tokens, and Stripe and Slack tokens [1]. Stolen data was encrypted using RSA encryption, with the attacker holding the private key, and exfiltrated to a public GitHub repository containing references to "Shai-Hulud: Here We Go Again" as well as an external domain at https://npm-cache[.]com:443/router [1].