Keyv and friends compromised in active Shai-Hulud supply chain attack
https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attackIt's time pre-install / post-install hooks were killed off. Start with a moratorium on any new ones.
For example:
find . -type f | grep -P "/Math_Symbol\.js$"Surely Github's software is good enough that an intern can slop the 80/20 together in a day? It would be an actually good use of AI spending.
https://github.blog/changelog/2026-07-28-npm-publish-time-ma...
Maybe that's the idea. Regards, the <insert your favourite 3 letter agency here>
Unless...
Maybe in 6 months.
NPM gets targeted a lot because it's popular. That's it.
How many instances of this are required before npm package maintainers learn?
To the point of the article: I don't know why GitHub still allows the release feature. It is complete insanity. Tar archives must be constructed manually and checked for leaked keys etc.
This is such lazy or click baiting writing. Who cares how many installations there are per month normally? The high install numbers are almost certainly from running in CI where such secrets don’t exist. How many installs actually occur in a non CI environment and of those how many were the compromised version?