npmsupply-chainmalware
Keyv Supply Chain Attack: 2 Billion Monthly Downloads Compromised in npm Worm
Attackers compromised the GitHub account of keyv maintainer jaredwray, injecting a credential-stealing worm into 434+ npm packages with 2B+ monthly downloads.