THREAT OPS › Threat News › Compromised keyv Maintainer Account Triggers Massive npm Supply Chain Attack
Compromised keyv Maintainer Account Triggers Massive npm Supply Chain Attack
<p>A compromised GitHub maintainer account was used to publish malicious versions of 10 widely-used npm packages in the keyv and cacheable ecosystem, collectively downloaded over 619 million times per month. The attack, attributed to the TeamPCP threat group, deployed a descendant of the “Mini” Shai-Hulud malware family that harvests cloud credentials, GitHub tokens, SSH keys, […
MITRE ATT&CK techniques
- CredentialsT1589.001