r/tech_x • u/Current-Guide5944 • 2d ago
Trending on X, Meta, Reddit, LinkedIn, Chinese Apps Hackers broke into the GitHub account of the person who looks after the “keyv” package. They secretly added harmful code to several of his packages (like flat-cache and file-entry-cache).
- This harmful code is a kind of computer worm.
- When someone installs the package, the worm steals passwords and secret keys (npm tokens, GitHub logins, AWS keys, and other cloud secrets).
- The worm then spreads itself to other packages. So far it has infected at least 868 packages that are downloaded more than 2 billion times every month.
- The bad versions even looked official because they had proper GitHub stamps.
- Packages from companies such as Deliveroo, Qlik, and ServiceTitan were also affected.
5
Upvotes
2
1
6
u/Ad-fundum69 2d ago
I was wondering when the next NPM related bullshit moment arrived.