A credential-stealing npm worm has infected 353+ versions of the npm registry, started as a result of attackers compromising the Github account behind Keyv. The malicious worm uses a preinstall script to gain repository, package registry, cloud and private key information. The bundle also harvests Github, action runners memory, and installs a token-revocation watcher. The data exfiltrated from victims is stored in a public repository under the string "Shai-Hulud: Here We Go Again."
Unnecessary install scripts should be disabled, and SafeDep versions should be compared to the affected version list.