feedd.›Tech
TechVentureBeat · 54d ago

The Shai-Hulud npm worm didn't fake its security check — it earned a legitimate one

An attacker compromised the GitHub account of keyv's maintainer and distributed poisoned versions across at least 868 packages with 1,381 total versions, accumulating over two billion monthly installs. The malicious releases carried valid provenance signatures that were legitimately earned rather than forged, presenting a new threat to supply chain security infrastructure.

Read full story →
More from Tech

OpenAI will not pursue an initial public offering in 2026 because the company is prioritizing safety concerns related to artificial intelligence technology. CEO Sam Altman made this statement in an interview with Fortune.

01

AI is increasingly integrated into home appliances, work products, and messaging systems while simultaneously gathering data from user behavior. Traditional cybersecurity threats like stolen passwords and phishing attacks have become more sophisticated, requiring four specific protective habits to reduce digital risk.

02

Three major music publishers sued Anthropic for allegedly using torrented music and lyrics to train AI models without permission, following a similar January lawsuit from Universal. Anthropic previously settled a 1.5 billion dollar case over pirated books and declined detailed comment on the music allegations.

03

Get feedd. daily

Top stories in your inbox every morning. Pick what you want.

No spam. Unsubscribe anytime.