keyv and cacheable npm Package Hijacked in Supply Chain Attack (Campaign)
ID: bad4dd89-f12a-57a1-8fed-a15b03998330
STIX ID: report--bad4dd89-f12a-57a1-8fed-a15b03998330
Feed Name: Wiz Cloud Threat Landscape
Threat Score
Date Published: 2026-08-04
Date Updated: 2026-08-06
Author: [email protected] (Wiz Threat Research)
...
...
A compromised GitHub maintainer account was used to inject IDE persistence payloads into the keyv repository and publish malicious npm package versions, creating a worm that has propagated to over 400 distinct npm packages; the incident involved data exfiltration and represents a widespread supply-chain compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
