logo

keyv and cacheable npm Package Hijacked in Supply Chain Attack

ID: 444d43df-e720-5367-b2b9-4573af2735e7

STIX ID: report--444d43df-e720-5367-b2b9-4573af2735e7

Feed Name: Wiz Blog

Threat Score
90/100

Date Published: 2026-08-04

Date Updated: 2026-08-04

Author: Merav Bar

...
...

Wiz Research is investigating an ongoing software supply-chain attack that began with a compromised GitHub maintainer account and resulted in malicious versions of keyv/cacheable ecosystem npm packages (now propagated to hundreds of packages). The malware is a variant of the 'Mini' Shai-Hulud family that steals cloud and developer credentials, attempts IDE/CI persistence, exfiltrates data via GitHub repos, and dynamically retrieves C2 domains from an Ethereum smart contract; the report includes affected package versions, file hashes, domains, user-agents, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.