An attacker hijacked the keyv/cacheable npm maintainer account and shipped a self-propagating Mini Shai-Hulud worm across 2 billion+ monthly installs, reaching most teams transitively through ESLint. Valid OIDC provenance masked the compromise. No CVE was assigned.
The post