The npm attack that turned provenance attestations into camouflage
A supply-chain attack on npm affected over 400 packages, including Keyv projects. This attack exploited provenance attestations, making them useless for security. Developers should review their dependencies and update packages to prevent further exploitation. The attack's impact is still being assessed.