Malware in flat-cache
Malware was discovered in the flat-cache npm package. Systems with the package installed or running are considered fully compromised, with potential for complete system takeover and credential theft.
- Disclosed
- Last updated
- Blast radius
- Any system with flat-cache installed or running
- Ecosystems
- Attack vectors
- Affected entities
- flat-cachenpm package
A malware incident was identified in the flat-cache npm package. According to the GitHub advisory, any computer with this package installed or running should be considered fully compromised.\n\nThe advisory recommends immediate action: all secrets and keys stored on affected computers should be rotated from a different, uncompromised system. While the malicious package should be removed, there is no guarantee that removal will eliminate all malicious software that may have been installed as a result of the compromise.\n\nThe scope of impact extends to any system where flat-cache was installed or executed, making this a critical supply chain incident affecting the npm ecosystem.
Indicators of compromise
- Packages
- flat-cache
Remediation
- Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer
- Remove the flat-cache package from all affected systems
- Conduct a full security audit of any system that had flat-cache installed
- Monitor affected systems for signs of unauthorized access or persistence mechanisms
- Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure
Sources
- GitHub Advisory GHSA-8jxr-wprf-45g8 · GitHub Advisory Database
Cite this entry
"Malware in flat-cache." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 4, 2026; last updated August 4, 2026. https://supplychainattack.org/incident/malware-in-flat-cache-i81v2w
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
Malware in internallib_v688
Malware discovered in the npm package internallib_v688. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in cacheable-request
Malware was discovered in the npm package cacheable-request. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in cache-manager
Malware was discovered in the npm package cache-manager. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2
ChainDrop is a self-propagating npm worm that publishes malicious versions of dozens of npm packages using stolen maintainer credentials. The worm harvests CI/CD credentials and uses an Ethereum-based dead-drop command-and-control mechanism.
ChaindropnpmOtherCompromised packageMalicious maintainerAccount takeover