Skip to main content

Tag: keyv

1 article

Cluttered software development workspace with laptop, papers, and cables.

Npm Worm Exploits Hundreds of Packages via Keyv Link

Hundreds of packages in the npm registry have been compromised by a worm exploiting a vulnerability in the Keyv library, with 353 poisoned versions across 79 package names verified. This malicious campaign uses a preinstall lifecycle command to spread and harvest sensitive credentials and secrets from various sources.

Analyst 207