logo

keyv and cacheable npm Package Hijacked in Supply Chain Attack (Campaign)

ID: bad4dd89-f12a-57a1-8fed-a15b03998330

STIX ID: report--bad4dd89-f12a-57a1-8fed-a15b03998330

Feed Name: Wiz Cloud Threat Landscape

Threat Score
90/100

Date Published: 2026-08-04

Date Updated: 2026-08-06

Author: [email protected] (Wiz Threat Research)

...
...

A compromised GitHub maintainer account was used to inject IDE persistence payloads into the keyv repository and publish malicious npm package versions, creating a worm that has propagated to over 400 distinct npm packages; the incident involved data exfiltration and represents a widespread supply-chain compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.