Shai-Hulud hits npm again: keyv and hundreds of packages
Malicious versions of keyv and related npm packages ran on their own during installation, pulled secrets from developer machines and CI runners, then published more infected packages. Here is how to check your exposure and what to do first.