THE WORM THAT USES YOUR CREDENTIALS TO SPREAD ITSELF

On August 4, 2026, an attacker compromised the GitHub account controlling keyv and the cacheable caching library family. They published a malicious keyv@6.0.0 with a preinstall hook carrying the Mini Shai-Hulud worm.

keyv has over 600 million monthly downloads (Elastic Security Labs, 2026, https://www.elastic.co/security-labs/shai-hulud-chaindrop-npm-supply-chain). Within 30 minutes, the payload appeared across nine unrelated organizations. By end of day, well over a thousand poisoned package versions sat in the npm registry (Phoenix Security, 2026, https://phoenix.security/mini-shai-hulud-keyv-cacheable-npm-supply-chain-worm/).

This is how it worked.

The worm steals developer credentials: npm tokens, GitHub personal access tokens, AWS keys, cloud credentials, environment variables. It reads ~/.npmrc, ~/.aws/credentials, GitHub token files, CI/CD secrets. Everything a developer has on their machine or in their pipeline.

Then it uses those stolen npm tokens to publish malicious versions of any package the compromised developer maintains. Self-propagation: you install poisoned keyv, the worm steals your npm token, the worm publishes a poisoned version of your package, someone else installs that, and the cycle continues. Exponential spread.

The stolen credentials are encrypted and pushed to attacker-created public GitHub repositories with descriptions like "Shai-Hulud: Here We Go Again" or exfiltrated to C2 domains fetched dynamically from an Ethereum smart contract. Decentralized infrastructure – difficult to takedown, censorship-resistant.

The malware also installs a background system service monitoring your GitHub token for revocation. If it detects a 4xx error (token revoked), it triggers payload re-execution. Persistence through credential rotation.

Here's the scope.

keyv: 600+ million monthly downloads (Elastic Security Labs, 2026, https://www.elastic.co/security-labs/shai-hulud-chaindrop-npm-supply-chain). Related packages: flat-cache (near 580 million monthly), cacheable-request (over 137 million monthly), cacheable (over 30 million monthly), cache-manager (over 16 million monthly downloads) (Elastic Security Labs, 2026, https://www.elastic.co/security-labs/shai-hulud-chaindrop-npm-supply-chain). These are foundational caching libraries used throughout the Node.js ecosystem – API clients, build tools, testing frameworks, session storage, HTTP caching.

Well over a thousand poisoned package versions means the attacker compromised hundreds of maintainer accounts via credential theft from earlier infections (Phoenix Security, 2026, https://phoenix.security/mini-shai-hulud-keyv-cacheable-npm-supply-chain-worm/). A worm cascade.

The attack vector was a compromised GitHub account. One account with publishing rights to the keyv organization gave the attacker the ability to publish to the entire cacheable family. npm runs preinstall scripts automatically before package installation. No user interaction. No confirmation. You run npm install, the preinstall hook executes, and your credentials are gone.

If you ran npm install in a CI/CD pipeline – GitHub Actions, GitLab CI, Jenkins – the worm stole your CI secrets and deployment credentials. If your .env files, AWS credentials, or database passwords were on that machine, the worm took them. If you maintain any npm packages, the worm published malicious versions under your name.

The C2 domains are stored on-chain in an Ethereum smart contract. The attacker can update the list without touching any server that can be seized or sinkholed. The credential dumps were pushed to public GitHub repositories disguised as normal commits. Stolen secrets sitting in public repos, indexed by search engines.

npm removed the malicious versions from the registry. GitHub took down the credential dump repos. But the credentials are already out. Every npm token, GitHub PAT, AWS key, and environment variable from every infected developer machine – stolen, exfiltrated, and sitting in the attacker's hands.

If your production credentials were on an infected machine, your production infrastructure is at risk. If your side projects, consulting work, or personal repos were on that machine, those credentials are compromised too.

The attack was active for weeks before the full scope was understood. Delayed detection. Widespread credential compromise. And every developer who installed the poisoned package became an attack vector for the next round of infections.

This is a supply chain worm. Self-propagating malware using stolen credentials to publish malicious packages. It's not the first Shai-Hulud variant – this one evolved from earlier campaigns with improved obfuscation, persistence, and exfiltration.

600 million monthly downloads (Elastic Security Labs, 2026, https://www.elastic.co/security-labs/shai-hulud-chaindrop-npm-supply-chain). Well over a thousand poisoned versions. Credentials from hundreds of developers, now in attacker hands. A worm that spreads by making victims into publishers.

Your move is rotating every credential that touched a machine where you ran npm install between August 4 and when you patched. npm tokens. GitHub PATs. AWS keys. Database passwords. API keys. CI secrets. Everything.

And then explaining to your security team how a caching library turned into a credential harvester that used your publishing rights to spread itself.