WorkThe story, in brief

Shai-Halud Supply Chain Campaign — Expanded Impact & Vercel Response

Over 40 npm packages pwned in coordinated supply chain attack. Vercel just disclosed how they caught it—and what founders need to do now.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

A major coordinated supply chain attack (Shai-Halud) compromised 40+ npm packages via wallet-drainer malware. While Vercel contained blast radius to ~10 customer projects, the incident exposes systemic risks in open-source dependency chains that every AI/tech startup relies on—and demands immediate token rotation and lockfile audits across infrastructure.

The key facts

8 to know
  1. 40+ npm packages compromised via Tinycolor 'worm' vector

  2. Original Qix compromise affected ~18 core packages (chalk, debug, ansi-styles)

  3. CrowdStrike npm namespace also trojanized with wallet-drainer malware

  4. ~10 Vercel customer projects directly impacted by compromised versions

  5. DuckDB maintainer account compromised; no Vercel customer builds affected

  6. Attack timeline: Sept 8 discovery → Sept 16 public disclosure (8-day window)

  7. Vercel response: blocklisted versions, purged caches, elevated monitoring thresholds

  8. Recommended mitigation: pnpm minimumReleaseAge setting (24hr delay), token rotation, lockfile pinning, GitHub workflow inspection

Go to the source

Vercel Blogvercel.com

Publisher excerpt: Summary Impact to Vercel Customers What We Did What We’re Watching & Doing Recommendations for Vercel Users Timeline References The supply chain campaign has escalated. What began with the Qix compromise affecting ~18 core npm packages (, , , etc.) has since spread:Shai-Haludchalkdebugansi-styles…
Read original report
Back to today's editionMore work news

The wider picture

View all
Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
AI illustration by KeyNews
Work01

AI staff complain of mental toll over fears of threat to society

AI researchers at frontier labs face psychological stress tied to existential concerns about their own work. This is a workplace and culture story within the AI industry that affects recruitment, retention, and decision-making at the labs building the frontier.

Financial Times Technology
Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
AI illustration by KeyNews
Work02

Burnham to call for global effort to control threats posed by AI

Major-power diplomacy on AI safety and control is moving from lab and boardroom into formal state-to-state negotiation. Practitioners and enterprises need to track regulatory momentum across jurisdictions.

Financial Times Technology
Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
AI illustration by KeyNews
Work03

OpenAI proposes development of global AI standards to guide alignment, RSI

A major lab is proposing formal governance structures for AI safety and alignment. This matters to practitioners building enterprise AI and to policy watchers — it signals how the industry may be regulated and what compliance burdens are coming.

CNBC Technology