Supply chain · free

Credential Half-Life Scorecard

A worm stole your npm token twenty minutes ago. It is already publishing. Nothing here asks whether you would have caught it — in the August 2026 keyv compromise the malicious packages were correctly signed and passed provenance checks, so detection was not the deciding factor. What decided each victim's blast radius was how long a stolen credential stayed useful. Eight questions, and every one assumes the token is already gone.

Written after the keyv and cacheable compromise — where valid signatures and passing provenance stopped nothing, and credential lifetime decided everything.

Question 1 of 80% complete
Publishing Credentials · This is the credential the worm uses to spread. Its theft harms people downstream of you, not just you.

How long is a package-publishing token (npm, PyPI, crates) valid for?

Credential Half-Life Scorecard — what a stolen token buys an attacker · PlayCISO