Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
ID: 6b98affa-7213-5cd5-a5bf-c22dd7e8b3e6
STIX ID: report--6b98affa-7213-5cd5-a5bf-c22dd7e8b3e6
Feed Name: Socket Blog
Socket's Threat Research Team documents an ongoing, active npm supply-chain compromise that injected a malicious `preinstall` hook into `keyv` and related `cacheable` packages; the hook downloads a Bun runtime to execute an obfuscated second-stage payload (`Math_Symbol.js`) that exfiltrates cloud and CI credentials, repackages and republishes trojanized packages via stolen npm tokens, and establishes persistence (including a dead-man's switch and autostart hooks targeting cloned repos). The report includes a detailed timeline, technical analysis, IOCs (file and tarball hashes, network endpoints), impact assessment, attribution commentary, and remediation guidance for developers and security teams.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
