It also used that access to inject a credential-stealing worm across the entire package family. The same maintainer owns cacheable (29M downloads/month), flat-cache (565M downloads/month), file-entry-cache (557M downloads/month), and several other widely-used caching utilities, all of which were swept up in the same attack.
The compromise was carried out by pushing malicious files directly to the main branch and then immediately cutting a new release, meaning the poisoned versions were published to npm with valid provenance signed by GitHub Actions.
The compromised packages include:
Mini Shai-Hulud malware was injected into keyv and eight related npm packages on August 4, 2026 after an attacker compromised the maintainer's GitHub account
www.aikido.dev
- keyv 6.0.0 (604M/month)
- flat-cache 6.1.24 (580M/month)
- file-entry-cache 11.1.6 (571M/month)
- cacheable-request 13.0.20 (137M/month)
- cacheable 2.5.1 (30M/month)
- @cacheable/memory 2.2.1 (28M/month)
- cache-manager 7.2.10 (16M/month)
- @cacheable/node-cache 3.1.2 (6M/month)
- @cacheable/utils 2.5.1 (34M/month)
- @cacheable/net 2.1.1 (3.7K/month)
- ecto 5.0.1 (4.5K/month)
We are also also seeing very active community spread of this supply chain worm to other maintainers and packages, including major organizations:
- @deliveroo/reevent 1.0.1
- @or-sdk/invitations 1.4.9
- @picsart/ai-sdk 3.32.2
- @qlik/embed-runtime 1.6.4
- picasso.js 2.11.6
Update — August 4, 2026, 13:37 CEST: At least 434 packages (across 1381 versions) have been compromised by the worm, with a combined total of over
2 billion monthly installs at the time of writing.