New npm Supply Chain Attack Began with the Keyv Library Compromised Hundreds of Popular Packages
06/08/2026-08:22 06/08/2026-08:25 מחשבים וטכנולוגיה Cyber Security News דיווח
A new npm supply chain attack has turned trusted software packages into a route for credential theft. The campaign began after attackers compromised the maintainer account behind the widely used Keyv library, then used that access to push malicious r
סיכום מאמר"נפץ בספליין האספקה של npm: תוכנה פופולרית נשלטת על ידי תופעי חבורה במתקפה החדשה של npm, תוכנה פופולרית נשלטת על ידי תופעי חבורה, שהחלה לאחר שמערכת הספליין של npm נפגעה. התוקפים חדרו לחשבון המתחזק של Keyv, ספריית תוכנה נפוצה, והשתמשו בזכות זו כדי להפיץ קוד זדוני.תוכן זה נוצר על ידי בינה מלאכותית.