Skip to main content
A Singapore Government Agency Website How to identify
Official website links end with .gov.sg
Secure websites use HTTPS
Look for a lock () or https:// as an added precaution. Share sensitive information only on official, secure websites.
Government officials will never ask you to transfer money or disclose bank log-in details over a phone call.
Cyber Security Agency of Singapore
Advisory

Ongoing npm Supply Chain Attack Affecting Keyv and Related Packages ("Shai-Hulud" Worm)

6 August 2026

Security researchers have identified an active software supply chain attack involving malicious versions of Keyv and related npm packages. The Shai-Hulud malware steals developer credentials and spreads by compromising additional packages. Organisations using Node.js should immediately review their dependencies and treat credentials on affected systems as potentially compromised.