npm Supply Chain Attack: Self-Propagating Shai-Hulud Worm Hits Millions

The global open-source software ecosystem is facing one of its most explosive crises to date. On August 4, 2026, cybersecurity research teams and international defense authorities—including the Cyber Security Agency of Singapore (CSA), Microsoft Threat Intelligence, Datadog, Wiz, and Palo Alto Networks Unit 42—issued urgent threat advisories regarding a massive, highly viral npm supply chain attack. Powered by a self-propagating worm variant from the “Shai-Hulud” malware family (also tracked as CHAINDROP or Mini Shai-Hulud), the operation infected over 1,300 package versions and 440 distinct npm packages in less than four hours. At the epicentre of the breach is keyv, a foundational key-value storage library in the Node.js ecosystem with over 120 million weekly downloads. As the malware systematically compromised downstream dependencies—including heavily relied-upon packages like cacheable, flat-cache, file-entry-cache, and cache-manager—the aggregate blast radius expanded to encompass software projects accounting for over 2 billion monthly downloads worldwide.
Written by
TempMail Ninja
Digital privacy and online security expert. Passionate about creating tools that protect users' identity on the internet.


