keyv and cacheable npm Package Hijacked in Supply Chain Attack
Wiz Research identified an ongoing supply chain attack affecting multiple keyv and cacheable npm packages. The attack appears to involve package hijacking, with investigation ongoing to determine full scope and impact.
- Disclosed
- Last updated
- Blast radius
- Multiple npm packages in the keyv and cacheable ecosystem; exact scope under investigation
- Ecosystems
- Attack vectors
- Affected entities
- keyvnpm package
- cacheablenpm package
Wiz Research is actively investigating an ongoing software supply chain attack targeting multiple npm packages in the keyv and cacheable ecosystem. The packages appear to have been hijacked, indicating a potential account takeover or unauthorized access to package maintainer credentials or the npm registry itself.\n\nThe investigation is ongoing, and the full scope of affected packages, versions, and downstream impact has not yet been fully disclosed. Organizations using keyv or cacheable packages should monitor for updates from Wiz Research and the package maintainers.
Remediation
- Monitor Wiz Research and npm security advisories for updates on affected versions
- Review package dependencies for keyv and cacheable usage
- Prepare to update to patched versions once available
- Consider temporary removal or pinning of affected packages until remediation is confirmed
- Check application logs for suspicious activity from these packages
Sources
Cite this entry
"keyv and cacheable npm Package Hijacked in Supply Chain Attack." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 4, 2026; last updated August 4, 2026. https://supplychainattack.org/incident/keyv-and-cacheable-npm-package-hijacked-in-supply-chain-attack-1270tg
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in @telekom-ods/react-ui-kit (npm)
@telekom-ods/react-ui-kit version 2.6.9 on npm contained malicious code in an install hook that exfiltrated system information (/etc/passwd, /etc/hosts, /etc/shadow, id output) via HTTP POST to an OAST callback server. The compromised package was published under the legitimate telekom-ods publisher account, suggesting either account takeover or supply-chain injection.
npmCompromised packageAccount takeover - activecritical
Malicious code in vite-plugin-cleaner (npm)
vite-plugin-cleaner contains a malicious postinstall script that fetches and executes code from an external GitHub repository (vite-cleaning-tools) without pinning to a specific commit or tag. This allows the maintainer or anyone with write access to that repository to execute arbitrary code on installer machines at any time without publishing a new npm version.
npmAccount takeover - activecritical
ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2
ChainDrop is a self-propagating npm worm that publishes malicious versions of dozens of npm packages using stolen maintainer credentials. The worm harvests CI/CD credentials and uses an Ethereum-based dead-drop command-and-control mechanism.
ChaindropnpmOtherCompromised packageMalicious maintainerAccount takeover - containedcritical
Malicious code in @antv/g6-extension-3d (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g6-extension-3d, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit