Keyv npm Supply Chain Attack Hits 2 Billion Installs

Keyv npm Supply Chain Attack Hits 2 Billion Installs

The Keyv npm supply chain attack compromised a single GitHub maintainer account and used it to push a credential-stealing worm into hundreds of widely used caching packages. By August 5, trackers put the count at 868 packages and 1,381 versions, spanning a combined 2 billion-plus monthly installs — the largest software supply-chain incident DIESEC has…

Read More

AsyncAPI npm Supply Chain Attack: No Token Stolen

AsyncAPI npm supply chain attack

The AsyncAPI npm supply chain attack shows that neither of the two controls teams were told to trust — cryptographic provenance and blocking install scripts — actually stopped it: an attacker published four trojanized packages with valid SLSA/OIDC provenance attestations, without ever stealing an npm token, and the payload runs regardless of –ignore-scripts. What Happened…

Read More

PolinRider Supply Chain Attack Hits 108 Packages

PolinRider supply chain attack

The PolinRider supply chain attack has been confirmed by Socket.dev, SecurityWeek and SC Media: a North Korea-linked actor has flooded four separate open-source ecosystems — npm, Packagist, Go modules and the Chrome Web Store — with 108 malicious packages designed to steal developer and cloud credentials. What Happened Researchers attribute the PolinRider supply chain attack…

Read More

Your AI agent framework was backdoored overnight. 144 packages. 1.1 million weekly downloads. The attack started with a dormant account.

Your AI agent framework was backdoored overnight. 144 packages. 1.1 million weekly downloads. The attack started with a dormant account. Here is what happened — and what it means for your development team. Mastra is the dominant JavaScript/TypeScript framework for building AI agents. On June 16, an attacker hijacked “ehindero” — a real former Mastra…

Read More