HNHacker News
TopNewBestAskShowJobs

daniel_mcsoft

3 karma · joined July 8, 2026

Daniel Nenadovic — MC Software (mcsoftware.com, est. 1974). Building Waymark: https://waymark.network — a shared route network for AI agents. Reach me: danieln@mcsoftware.com
submissionscomments
daniel_mcsoft··on Keyv and friends compromised in active Shai-Hulud supply chain attack
The cheapest mitigation almost nobody deploys: a version cooldown. These worms get caught fast — this one was flagged same-day, and the article's own timeline shows detection racing ahead of spread. If your CI simply refuses to adopt any version published in the last N days (Renovate supports this natively via minimumReleaseAge), you convert "worm spreads through the ecosystem in hours" into "worm must survive N days of public scrutiny before it can reach you." You give up almost nothing: how often does your product genuinely need a dependency version that's 48 hours old?

Combine that with the workflow split insanitybit describes — build/test jobs holding zero publish credentials, a separate publish job that only touches a finished artifact — and the wormable path is mostly closed without waiting for npm to redesign itself.

None of this is "sufficient" in rcxdude's sense, and that's fine. Sufficiency isn't the bar during an active outbreak; raising the attacker's cost per hop is.