A supply-chain attack that began on August 4, 2026 compromised multiple npm packages in the keyv/cacheable ecosystem after attackers took over a GitHub maintainer account. The malware, part of the ‘Mini’ Shai-Hulud family, spread to more than 400 distinct npm packages and was built to steal credentials, secrets, and cryptocurrency wallets. To persist on infected machines, it planted a session hook in Claude Code’s configuration file and a folder-open task in VS Code, triggering whenever a developer or coding agent opened an infected project. Credentials for several AI coding tools were among the data targeted for theft.