Worm compromises hundreds of popular npm packages
ID: 135e6b15-7700-5188-b045-ad20f566f59c
STIX ID: report--135e6b15-7700-5188-b045-ad20f566f59c
Feed Name: Datadog Security Labs
Threat Score
On 2026-08-04 a widespread npm supply-chain campaign was observed that injected a two-stage loader into popular packages (including keyv, cacheable, and ecto) to execute a Bun-based second stage which harvests secrets (GitHub, npm, cloud, CI, Kubernetes, Vault, AWS), exfiltrates encrypted data using an Ethereum smart-contract dead-drop or GitHub repository fallback, and propagates by publishing malicious package updates and committing repository hooks and workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
