a hacked github account just turned npm into a credential-stealing worm

One compromised maintainer account, ten trojanized packages, two billion downloads a month — and the malware is specifically hunting for your Claude…

Aliteq
Priya Nair · Software & Systems Editor

What happened, fast

An attacker compromised the GitHub account of Jared Wray, maintainer of npm's keyv and cacheable package families, and published malicious versions between 09:35–10:14 UTC on August 4, 2026.

What happened, fast

Ten packages were directly trojanized, including keyv@6.0.0, cache-manager@7.2.10, and cacheable-request@13.0.20; self-propagation reached over 400 npm packages total, per Wiz.

What happened, fast

The payload steals cloud credentials (AWS, GCP, Azure, Vault, Kubernetes), CI/CD secrets, crypto wallets, and AI coding assistant configs for Claude, Cursor, and Codex.

What happened, fast

Researchers attribute the malware to the 'Mini' Shai-Hulud family, sharing code with earlier worm campaigns this year including TeamPCP and @antv.

What happened, fast

No CVE has been assigned as of publication — this is being tracked purely through vendor advisories and shared IOC lists.

The nastiest part: a dead-man's switch

This isn't just smash-and-grab credential theft. Researchers at Socket found the payload plants a persistent monitor — at ~/.local/bin/gh-token-monitor.sh on infected machines — that watches for its…

Aliteq

Read the full story

a hacked github account just turned npm into a credential-stealing worm

Read the full story on Aliteq