logo

Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)

ID: d0c62733-355b-5dae-be11-46b1619065a4

STIX ID: report--d0c62733-355b-5dae-be11-46b1619065a4

Feed Name: SANS ISC Diary

Threat Score
90/100

Date Published: 2026-08-05

Date Updated: 2026-08-05

ADMIRALTY:B6
...
...

A widespread npm supply-chain campaign (keyv/cacheable) published trojanized packages with a preinstall loader and IDE autostart hooks that harvest cloud and CI credentials, then use stolen npm tokens to worm into additional packages; the payload also installs a dead-man's switch that polls GitHub with the stolen token and executes an attacker-controlled handler if the token is revoked, so incident responders should isolate affected hosts and preserve evidence before revoking credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.