Security1 distinct publisher3 min readUpdated
The poisoned keyv releases were signed by GitHub Actions and the attestation was accurate. It certified a build whose source had already been taken over.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The poisoned keyv releases were signed by GitHub Actions and the attestation was accurate. It certified a build whose source had already been taken over.
On August 4, according to an SC Media Perspectives commentary, someone took over the GitHub account behind keyv, a caching library with roughly 127 million weekly downloads, pushed code from a new Shai-Hulud campaign to the main branch, cut a release, and published it to npm carrying valid provenance signed by GitHub Actions [1] [2] [3]. That last clause is the finding: the attestation was correct, because the attacker committed through the project's real repository and triggered its real workflow, so the pipeline honestly certified a poisoned build [7].
Anyone who read attestation as a verdict got exactly what the control promises and nothing they actually needed. Build provenance proves where and how a package was compiled and published; it says nothing about whether the source that went in was trustworthy [6]. After the first three waves, the commentary notes, industry guidance had converged on two controls: scan dependencies, demand attestation [8]. Both are worth doing, and neither answers the question at install time. Signing infrastructure inherits the trustworthiness of whoever can trigger it, so a compromised maintainer account produces a faithfully signed malicious release with no cryptography broken anywhere [9].
The scale numbers followed from automation, not from attacker effort. Within hours the worm reached more than 1,280 packages representing more than 2 billion monthly installs, with researchers at Aikido Security and Endor Labs watching 50 to 100 new packages fall every few minutes [4] [5]. Note that keyv alone, at 127 million weekly downloads, is on the order of a quarter of that headline install figure, so the 2 billion is a measure of blast radius, not of how many separate compromises occurred [18]. The spread mechanism was continuous integration: build runners install transitive dependencies and hold publishing tokens for service accounts, and the payload harvested those tokens and republished poisoned versions of each victim's own packages with no human attacker in the loop [15].
The execution path is built to defeat scanning as well. Every infected package carried a preinstall hook and a file named setup.mjs, an obfuscated dropper that pulls down the Bun runtime and uses it to run a 728 KB payload called Math_Symbol.js [10]. The stealer runs in memory and finishes before npm install does, leaving almost nothing on disk to find [11]. It goes after npm and GitHub tokens, AWS credentials, Kubernetes secrets, HashiCorp Vault tokens, and Stripe and Slack keys [12], and sweeps roughly 200 filesystem patterns for SSH keys, Terraform state, Docker registry credentials, KeePass databases and VPN configuration [13]. The results were encrypted and pushed to a public GitHub repository described as "Shai-Hulud: Here We Go Again." [14]
The remediation list in the commentary is unglamorous and cheap: turn install scripts off by default in CI, pin versions and use overrides, rotate on the assumption of exposure rather than evidence of it, stop treating attestation as a decision, and place a control at the moment code executes [16]. The pinning advice matters most for teams that audited direct dependencies and found nothing, since the affected caching libraries are usually transitive [17].
Watch whether the post-wave guidance changes shape. If the answer remains scan and attest, the fifth wave has the same entry point available: one maintainer session, one real workflow, and a signature that verifies [9] [7].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Within hours the worm had spread to more than 1,280 packages representing more than 2 billion monthly installs.
Researchers at Aikido Security and Endor Labs were watching 50 to 100 new packages fall every few minutes.
The commentary's five recommended steps: disable install scripts by default in CI; pin versions and use overrides; rotate on the assumption of exposure rather than evidence of it; stop treating attestation as a verdict; and put a control at the moment of execution.
On the morning of August 4, someone took over the GitHub account behind keyv, a caching library with roughly 127 million weekly downloads.
The attacker pushed malicious code from a new Shai-Hulud npm campaign straight to the main branch and cut a release.
The poisoned versions were published to npm carrying valid provenance, signed by GitHub Actions.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single vendor-authored commentary, no primary advisory
Everything in the cluster comes from one SC Media Perspectives column written by a vendor marketing executive. The technical description is specific and internally coherent (preinstall hook, setup.mjs, Bun runtime, 728 KB Math_Symbol.js, roughly 200 filesystem patterns), and the central analytic claim about provenance semantics is self-evidencing reasoning rather than an assertion needing corroboration. But the incident-scale numbers are attributed to Aikido Security and Endor Labs without a linked report, no registry or maintainer statement appears, there are no hashes or package inventories, and no second publisher in the cluster confirms any element.
Broad reported spread, single-sourced and unconfirmed
Real-world impact is claimed at scale - a top-tier caching library, more than 1,280 packages, more than 2 billion monthly installs, automated republication through CI service-account tokens - and the mechanism described (build runners installing transitive dependencies while holding publish tokens) is a plausible amplifier that would touch many organisations. The score is held mid-range because every impact datum traces to the same commentary, no remediation status or exposure window is given, and no affected downstream organisation is named.
Sound core argument, unverified numbers and a vendor-shaped conclusion
The piece is more disciplined than typical incident commentary - it explicitly dismisses the two-billion figure as the least useful part of the story and grounds its thesis in what provenance does and does not attest. Overstatement enters at two points: headline scale numbers presented as established while resting on uncited third-party observation, and a closing prescription to 'put a control at the moment of execution' that maps onto the author's employer's product category without any comparison of alternatives such as account hardening, trusted publishing or install-script policy at the registry level. Net effect is mildly overstated relative to the evidence supplied.
Vendor CMO recommending his own control category
The byline identifies the author as chief marketing officer of Morphisec, and the argument arrives at the conclusion that scanning and signing are insufficient because both act before code runs, so a control is needed at the moment of execution - the runtime-defence pitch. The publisher labels the column as community Perspectives content striving to be non-commercial and no product is named, which tempers but does not remove the alignment between the analysis and the author's commercial interest.
Coherent mechanism, thin and conflicted sourcing
Confidence rests on a single conflicted source with no corroboration, which caps it well below the midpoint. It is not lower because the structural argument about provenance is verifiable on its own terms, the technical detail is specific enough to be falsifiable, and the named third-party researchers and the identified library give a clear path to confirmation once primary advisories are available.
build
1,400 npm maintainer domains, 18 flags, and one word doing too much work1 distinct publisher
build
A file-copy Allure adapter for Katalon, and the history IDs that make retries useful1 distinct publisher
build
The npm audit that works because it never installs the package1 distinct publisher
security
The 2,500-org compromise was a Trivy problem. LiteLLM was the closing act.1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 20, 2026