ATRIUMsearch → argument graph
FactVideo · 1:12 — 3:14

A new Shy Halute-style worm compromised 868 packages carrying over 2 billion monthly installs, and the mitigation is to block packages not yet available for a day and prefer PNPM.

Scott reports an active supply-chain worm (started via the Keeyv package) that has hit 868 packages and 2 billion monthly installs, dropping a stealer that sweeps npm, GitHub, AWS, Kubernetes, and Vault secrets and spreads to other maintainers. ✦ AI generated

Scott (Host) · Syntax · 2026-08-04 · original ↗

starts at this moment · 1:12

today there is a new Shy Hallude attack going down and one which has already compromised 868 packages carrying over 2 billion monthly installs... the main package that was compromised it started with this Keev package... the advice that we always give you on these worms is that you should be setting your packages not to install things that have not been available for at least a day or so. PNPM, npm, they all have this feature. Um so PNPM has it by default... A pre-install hook fires on npm install and drops a stealer that sweeps npm, GitHub, AWS, Kubernetes, and Vault secrets and then spreads to more maintainers.

verbatim transcript · starts at 1:12

Transcript · around this moment

1:12packages carrying over 2 billion monthly installs. Uh so the seems like the main package that was compromised uh it started with this Keev package which I haven't used. Have you guys used this one? >> No, I don't believe so. But you never know if it's all the way down the dependency tree. >> Dependency. >> It's a it's a key value in cachable. Um uh it's a key value library that I it

1:42seems like it has quite a lot of people using this. So this is a a library that well was compromised and now the worm is doing worm stuff and a ton of other packages have been compromised. So the folks the advice that we always give you on these worms is that you should be setting your packages not to install things that have not been available for at least a day or so. PNPM, npm, they

2:10all have this feature. Um so PNPM has it by default. easiest solution is to just use PNPM. It's a a great package manager in the first place. But just scrolling through this list, it's just another one of these big old worms that's coming up to slurp up all of your stuff, which is really the the thing here is that it it's it's trying to it's trying to grab

2:35your um enviables. It's trying to grab all kinds of stuff. Again, a pre-install hook fires on npm install and drops a stealer that sweeps npm, GitHub, AWS, Kubernetes, and Vault secrets and then spreads to more maintainers. This is the same type of worm that we've seen over and over and over again. I think this is like the fifth or fourth shy hall that we've seen recently >> this year. This year alone. Yeah. In the

3:04last six, seven months. >> So, uh, be careful out there, folks. There's a CSV of a ton of packages that have been hit from this bad boy. >> One interesting thing about all of these attacks is that you're not hearing these stories of there was an attack and these Bitcoin wallets were drained immediately. You're often hearing there was all of these attacks and then we don't often hear too much follow-up of

3:27like what actually happened. And shout out on Friday, I'm releasing a video on the like black market of AI tokens. And and what I'm learning is that a lot of these hacks, they're they're stealing your AI tokens or they're stealing access to your um to whatever app you have and then they are just just stealing enough that you won't notice it. And they're selling those on the the

Around this claim