Keyv's Signed npm Releases Carried a Credential-Stealing Worm
A compromised maintainer account published Keyv-family packages with valid provenance, an install-time credential stealer, and code that could poison more npm releases.
Reader edition
A static, low-bandwidth edition for Kindle and other e-ink browsers. Articles retain their cover images, technical figures, captions, and source links.
Bookmark this static edition for low-bandwidth reading. No account, script, display preference, or device detection is required.
A compromised maintainer account published Keyv-family packages with valid provenance, an install-time credential stealer, and code that could poison more npm releases.
Gitea 1.22.1 through 1.27.0 can let an anonymous request read files as the service account, expose the internal token, and plant a Git hook that executes during a clone.
Unit 42 showed three post-compromise paths from Chrome's local passkey state to silent assertions, substituted verification keys, or the master secret protecting synced credentials.
INC ransomware activity raises the cost of treating an SMA 1000 hotfix as closure: affected appliances need log and configuration triage before defenders can trust them again.
Chrome's AI-scaled security pipeline fixed more bugs in two milestones than in the previous 23, making verified browser relaunch and fleet version state the practical enterprise control.
N-central operators need build 2026.3.1.7 and a downstream endpoint hunt because attackers used the RMM console to reach managed systems and establish persistence.
An integration error routed wallet entropy through MicroPython's deterministic Yasmarang fallback. Updating prevents new weak seeds, but existing ones still require migration.
A compromised Adform tracking file used browser events, DOM observers and form-field hooks to keep substituting Bitcoin, Ethereum and Tron addresses.
A crafted image can reach unsafe libvips operations through Active Storage, exposing files and process credentials that a Rails-only update cannot recover.
A ServiceWorker and SharedWorker combine a clean Bun runtime, delivered PE sections, and locally generated bytes before a same-origin download.
A poisoned build can start a memory-resident loader, re-arm through macOS preferences, and seed more projects, Git hooks, and archives.
A crafted AD CS chase sent the CA to rogue directory services. July updates add a real-DC check, but defenders still need issuance and replication evidence.
IPMI's RAKP exchange exposes material for offline password cracking, leaving defenders with a management-plane incident that host telemetry may miss.