A software supply chain compromise hit the JavaScript ecosystem after malicious versions of Keyv and related npm packages were published through legitimate maintainer workflows, with keyv@6.0.0 identified as a primary malicious release. Researchers said the tainted packages added a preinstall hook that executed attacker code during dependency installation on developer workstations and CI runners, while some repositories also contained malicious VS Code and Claude Code configuration files that could trigger execution when a cloned project was opened. Early community reports tied the incident to the jaredwray/cacheable package set and warned that numerous downstream dependencies were exposed.
Analysis found the malware targeted high-value secrets including GitHub and npm tokens, cloud credentials, Vault tokens, Kubernetes service account tokens, SSH keys, and TLS certificates, with tradecraft resembling the Shai-Hulud malware family. Investigators reported no evidence that npm itself was breached; instead, the attackers appear to have used stolen maintainer credentials and trusted GitHub Actions publishing pipelines with valid provenance and npm attestation, demonstrating that provenance verified the build source but not whether the source had already been maliciously altered. Responders were urged to avoid affected versions, isolate any host that installed them, remove persistence such as gh-token-monitor, and rotate exposed credentials from a clean system.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
Sonatype Research Labs reported that the August 4, 2026 Mini Shai-Hulud npm campaign had affected 2,225 tracked component versions, expanding the known scope beyond earlier public counts. The report said the activity spread from the keyv and cacheable ecosystems into packages maintained by additional organizations, including the @servicetitan namespace.
Wiz reported that the npm malware retrieved its command-and-control domains via eth_call from an Ethereum smart contract named StringListStore, allowing operators to change infrastructure without modifying the payload. The report said on-chain history showed the contract was initially configured with three domains and was later updated to return only npm-cache[.]com.
On 2026-08-04, SafeDep expanded its registry-backed count of the npm worm campaign to 1,684 poisoned versions across 420 package names tied to nine organizations, showing the compromise was far larger than earlier estimates. The report also documented alternate repository-based execution paths through Claude Code and VS Code workspace hooks in the Keyv repository.
OX Security described the Keyv/Cacheable incident as a broader npm malware campaign it called 'Shai-Hulud,' claiming more than 350 compromised packages and aggregate exposure above 2 billion monthly downloads. The report added technical details including GitHub-based credential exfiltration and propagation, commit tags reading 'Shai-Hulud: Here We Go Again,' and additional indicators of compromise.
On 2026-08-04, Socket Research Team published an analysis of the active Keyv/Cacheable npm supply-chain attack, detailing Bun-based staging, the Math_Symbol.js second-stage payload, broad credential theft targets, GitHub and DNS exfiltration, and persistence through systemd, LaunchAgent, .claude, and .vscode hooks. Socket said the malware used compromised maintainer credentials and npm OIDC trusted publishing to republish infected packages with valid attestations, and assessed the activity as aligned with the Shai-Hulud worm.
At 11:16 UTC on 2026-08-04, Snyk found that eight malicious releases were still tagged latest on npm, while three had already been removed: flat-cache@6.1.24, cacheable-request@13.0.20, and cache-manager@7.2.10. This captured the early containment state of the compromised package set.
ecto@5.0.1 was published at 10:28:01 UTC on 2026-08-04 after the first public warnings, and its setup.mjs and Math_Symbol.js files were byte-identical to those in keyv@6.0.0. This showed the malicious publishing activity continued even after the incident had become publicly visible.
Researchers observed additional malicious publications on 2026-08-04 affecting packages tied to HubSync, Qlik, OneReach, Ornikar, Deliveroo, ServiceTitan, Picsart, and others in rapid succession. SafeDep reported hundreds of poisoned versions published at scale across many package names.
Within the next hour on 2026-08-04, related packages in the Cacheable ecosystem were republished with malicious versions, including flat-cache, cache-manager, cacheable-request, file-entry-cache, and multiple @cacheable packages. Researchers concluded the attackers were using compromised maintainer accounts and legitimate release pipelines rather than breaching npm itself.
On 2026-08-04, attackers modified the Keyv GitHub repository around 09:00 UTC and shortly afterward published malicious keyv version 6.0.0 to npm using the project's normal trusted publishing workflow. The release added a preinstall hook that executed attacker-controlled code during installation.
Orca Security attributed the Keyv/cacheable npm supply-chain attack to the TeamPCP threat group and said the malware was a descendant of the Mini Shai-Hulud family. The report also noted the attackers used compromised GitHub Actions workflows to publish malicious packages with valid provenance signatures.
Snyk published advisory SNYK-JS-KEYV-18515941 covering the incident and classified keyv@6.0.0 as embedded malicious code under CWE-506. At the time of publication, no CVE or GitHub Security Advisory had yet been assigned.
A Reddit post in r/sysadmin reported an apparent npm supply-chain compromise involving the jaredwray/cacheable project and linked to GitHub issue #1692. The post said many downstream packages were affected and described the compromise as appearing self-replicating.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 40 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
28 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcethenewstack.io
Open sourcecryptika.com
Open sourcemalware.news
Open sourceresearch.jfrog.com
Open sourcegithub.com
Open sourcelabs.beazley.security
Open sourcesafedep.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.