00:00
2026-08-29
okaneland.com
ai-safety
A worm is after your AI keys. The install is the door.
On August 4, 2026, a malicious commit to the npm package 'keyv' triggered a supply-chain worm that compromised over 400 packages (Elastic) or over 1,300 package versions (Singapore's CSA), totaling mo…