/tag
On 4 August 2026, a worm infected 444 npm packages and 2,212 versions in under four hours. Every bad version carried a valid signature. The attacker never stole an npm token — they took a GitHub account and let the maintainer's own release pipeline sign the malware. Here is how it worked, why signatures did not help, and the four settings that would have stopped it.