Overview

Ongoing wave of wormable credential-stealing attacks against the npm registry through 2026, centered on shai-hulud-worm / miasma-worm tradecraft and the trust gap around trusted-provenance.

Timeline

  • 2026-08-04: keyv/cacheable maintainer compromise → 1,280+ packages / 2B+ monthly installs claimed (2026-08-04-devops-shai-hulud-1280-packages)
  • 2026-06-09: npm v12 announced — install scripts off by default
  • 2026-06-01/05: miasma-worm hits Red Hat packages and Microsoft GitHub repos
  • 2026-05: Earlier Mini Shai-Hulud waves (TanStack, DurableTask, etc.)

Key Players

Analysis

Provenance-backed malicious publishes show that CI identity attestation alone is insufficient. Install-hook malware + stolen tokens create exponential maintainer-graph spread. Runtime defenses (runtime-exploit-blocking) and stricter package-manager defaults are converging responses.

Sources