A self-propagating npm worm hit keyv and 400+ packages
The 'Shai-Hulud: Here We Go Again' worm compromised a maintainer account and spread through the dependency graph via preinstall hooks — a reminder that your build pipeline runs with production credentials.