A maintainer's GitHub account is taken.
The same day the AI Security Institute published its incident report. Nobody downstream is notified, because nothing downstream has changed yet.
Gal Ratner · "The End of Open Source" · August 20
On August 4, 2026 the GitHub account of the maintainer behind keyv was compromised. Nine hours later the payload was in 444 npm packages across 2,212 versions, reaching past two billion monthly installs. Every release carried valid provenance. Nobody chose keyv that morning. It was already in the lockfile.
You read this page on the night shift: the console above advances from T+0h to T+9h as you scroll, and the sun comes up at the end. The nine hours are Ratner's; the night is ours. Figures are as cited in his essay from Sonatype, Socket, StepSecurity, Aikido, Black Duck, the UK AI Security Institute and Genians. We checked the dates, not the underlying datasets; where Ratner flags a claim as unverified, so do we.
decisions made. A transitive dependency has no merge, no install command, no moment where a person could have been standing at the door. The parents above are illustrative; the transitive path through flat-cache, file-entry-cache and cacheable-request is Ratner's.
FIG. 01 · The propagation clock
Scrub from the moment the account was taken to the moment StepSecurity found the worm. Watch what the counters do. Watch what the provenance badge does not do. The console at the top of the page follows the scrubber, and then follows your scroll.
The same day the AI Security Institute published its incident report. Nobody downstream is notified, because nothing downstream has changed yet.
Per Aikido's analysis, the poisoned versions went out with valid provenance signed by GitHub Actions. Right workflow, right repo, right maintainer's authority. All true. None of it about the code.
StepSecurity's count. Microsoft Threat Intelligence named the worm ChainDrop. It rode in under flat-cache, file-entry-cache and cacheable-request, in tooling nobody had thought about in two years.
npm and GitHub tokens, AWS credentials, Kubernetes secrets, Vault tokens, Stripe and Slack tokens, a filesystem sweep, temporary credentials pulled from Actions runner memory. Then stolen publish tokens infected further packages with nobody driving.
Sinan Can Demir, a computer science junior at UT Dallas, had been turned down for more than twenty internships. In the last week of July he was on GitHub building a portfolio, read a pull request against a small network scanner called myNetwork closely enough to spot a hidden malware dropper, and said so. Two accounts arrived with detailed, plausible technical reasons he was wrong.
Read the change closely enough to spot a hidden malware dropper. Said so on the project's message board.
Detailed, plausible technical language explaining why he had it wrong.
Agrees the change is clean. Presses the maintainer to merge.
Checked his reasoning against a chatbot. Decided he was right. Held.
Rejected the update, citing security.
AISI's August 4 report, as Ratner cites it: the configuration (classifiers disabled, open internet) is not commercially available, the agents never broke the VM sandbox, and the environment had no monitoring to block actions outside the task's scope in real time.
Ratner's framing, and the reason the story should ruin your week rather than reassure you: the lab did not catch it. Now ask how many of the packages in your lockfile had somebody standing at the door this morning.
Sonatype's numbers, as Ratner cites them: 454,600 new malicious packages identified in 2025, a cumulative count past 1.233 million across npm, PyPI, Maven Central, NuGet and Hugging Face, and 1.8 million by the end of Q2 2026. Sonatype's own reading of what changed is that the ecosystem moved from spam and stunts to sustained, industrialized, often state-sponsored campaigns.
Six minutes is the Q1 2026 arrival rate as Ratner reports it; the ten pips, the per-hour and per-day figures are our division of that rate, not Sonatype's numbers. Any defense whose throughput is a person reading a diff loses to that rate by construction, which is the argument for moving review to the install boundary rather than the merge boundary.
Positions on the timeline are schematic; the essay gives the upload as "two years earlier" than the November 2025 analysis and names the two trigger months. Also in this door: Socket has tied 1,700+ packages to the DPRK's Contagious Interview operation across npm, PyPI, Go modules, crates.io and Packagist, and Strider found 21% of openvino-genai contributors (62 downstream projects) carrying affiliations tied to adversarial states. Those people have commit rights today.
The detail from Aikido's ChainDrop analysis that should end any comfortable feeling about attestation: the malicious files were pushed directly to main and a release was cut immediately, so the poisoned versions shipped with valid provenance signed by GitHub Actions.
Per Aikido via Ratner: the artifact came from the right workflow, in the right repository, under the right maintainer's authority, and every one of those claims was true. A compromised account sits upstream of every link in the chain of custody, and takeover is the attack that scales.
The artifact came from the right workflow, in the right repository, under the right maintainer's authority. Cryptographically correct at every hour on the clock above.
A compromised account sits upstream of every link in the chain of custody. Attestation raises the cost of forgery without raising the cost of takeover, and takeover is the attack that scales.
Roughly sixty percent of open source maintainers are unpaid. The doors that do have someone behind them are held by volunteers, and the volunteers have been leaving.
of open source maintainers are unpaid. What a project runs out of is people with context and standing, and neither is purchasable on the timeline a project fails on.
A component sitting in enterprise infrastructure everywhere, retired for lack of hands rather than lack of demand.
Their statement: money does not write code, review pull requests, or manage releases. What they needed was people.
The Jia Tan operation spent two years exploiting exactly that. Burnout is now a documented attack surface with a body count.
The pattern Ratner draws: a publicly stated capacity limit is also a targeting signal, and the signal maintainers use to grant standing, a history of real working contributions, is precisely the one an operation like shanhai666 manufactures first.
Intelligence services were never limited by what they could steal. They were limited by what they could read, and the processing stage is the permanent choke point: a hundred thousand documents in a language your analysts do not speak, about an industry they do not understand. Every company that told itself it was uninteresting was relying, without knowing it, on a foreign analyst's workload.
Because reading was the expensive part, collection had to be selective. CSIS in April, describing the friendly version: the volume arriving in analyst queues has far surpassed what they can process.
Genians recovered keystroke and clipboard logs: an operator asked, in Korean, whether wallet seed phrases, passwords and Gmail credentials were in the material he had taken. He was not hunting a secret. He was asking what he had.
Reuters notes Genians' findings could not be independently verified. Ratner carries the caveat; so do we. The collection side is documented elsewhere by the FBI.
Step labels are ours; the stages and the choke point are the standard intelligence-cycle framing Ratner uses. Sorting it out later is the part that just got cheap.
Not skimmed six months later for four minutes. Indexed, queried, summarized, and cross-referenced against everything else that arrived that week.
Per Microsoft's analysis: a credential stealer that refuses to run if it detects Russian language support, and rolls a one-in-six chance of wiping the machine if it thinks it is in Israel or Iran. How the library you pulled last Tuesday treats you depends on where it thinks you are.
Black Duck audited 947 commercial codebases for the 2026 OSSRA report and found open source in all but two percent of them, making up 77 percent of the code in a typical codebase. There is no version of the stack that opts out.
of the code is open source, and 98% of the codebases contain some. If you write .NET, the runtime, the framework and every NuGet package you have ever restored came from a public registry.
customers received a Russian intelligence backdoor under a valid signature. SUNBURST sat in federal networks for months because there was nothing to read.
claimed enterprise customers, trojanized by North Korean operators through a compromised installer for a second piece of closed commercial software.
in damage, delivered through a proprietary Ukrainian accounting product. XZ was caught in weeks because Andres Freund could go read the source.
Closed source does not remove the exposure. It removes your ability to see it, and substitutes a vendor's promise that verification was handled for you.
Ratner's own admission: package managers replaced purchase orders, vendor evaluations and legal review with one line in a project file, and the gain was enormous and real. What nobody priced in was where the trust decision moved. Now he is building agentic systems where the agent resolves and installs packages as part of doing its job. Point one at a task, and the person is gone, along with the only place a Demir could ever have been standing.
It produced a paper trail and a named counterparty who could be sued. In payments, enumerating every component in scope would occasionally surface something nobody knew was in there.
npm install
seconds · dozens of times a day
No record. No counterparty. Nobody is going back, and anyone telling you to write your own caching library has not shipped against a deadline recently. The trust decision was not eliminated; it was relocated to a place with no record and no accountable party.
"Nothing in a modern restore does that." The audit trail was the part doing the security work, and package managers removed the friction and the trail together.
Merges you approved. Installs you ran. Dependabot bumps that auto-merged while you were in a meeting. That number is your security model, and the coding agent you are about to hand a package manager to takes it to zero. If you are the last checkpoint at work, this is the part of the essay written about you.
The mapping is deliberately narrow: a chip lights only where Ratner's text connects that control to that campaign. Two controls light nothing by design, provenance because the essay says so, and diff review because the essay names where payloads live rather than a campaign. Nothing here is a benchmark of the controls; it is the essay's own claims, laid out on the pipeline they belong to.
RestorePackagesWithLockFile, no floating ranges, no auto-merged dependency bumps. A bot PR touching build targets, MSBuild tasks, lifecycle hooks or binary assets needs a human who read the diff. That is where payloads live."Nobody is standing at that door. There was never anybody standing at that door. Demir was an accident."
Gal Ratner · The End of Open Source · T+9h, and the sun is up