Summary
An attacker compromised the GitHub account of a keyv library developer, leading to the distribution of a credential-stealing "Shai-Hulud" worm through poisoned npm packages. This attack is particularly concerning because the malicious releases carried legitimate provenance signatures, demonstrating how attackers can exploit trusted supply chain mechanisms.