logo

“Old Father Eternity”: Shai-Hulud Worm Strikes a 6th Time – keyv/cacheable npm Supply Chain Attack

ID: 20dca371-7b0e-5fe2-8a8a-7717114a615e

STIX ID: report--20dca371-7b0e-5fe2-8a8a-7717114a615e

Feed Name: Checkmarx Zero

Threat Score
90/100

Date Published: 2026-08-05

Date Updated: 2026-08-06

Author: Bruno Dias

...
...

Checkmarx Zero reports an active, large-scale npm supply-chain campaign (a Shai-Hulud variant) that injects malware into widely used packages (e.g., keyv, cacheable), steals credentials from over 200 file paths and cloud metadata endpoints, and self-propagates across npm packages and GitHub repositories using sophisticated multi-channel C2 (including an Ethereum smart contract and GitHub commits). The report includes IoCs (malicious filenames, hashes, domains, an Ethereum address, malicious workflow/branch names), lists affected package versions, outlines the six-stage attack chain, and provides containment and remediation steps including credential rotation, artifact scanning, and blocking malicious package versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.