Type
Campaign
Actors
Pub. date
August 4, 2026
Initial access
Maintainer account compromise
Impact
Data exfiltrationSupply chain attack
Observed techniques
Observed tools
Status
Finalized
Last edited
Aug 5, 2026 12:30 PM
Multiple npm packages in the keyv/cacheable ecosystem were compromised following the compromise of a GitHub maintainer account, resulting in the publication of malicious package versions. All versions shared a consistent payload. Starting at 9:00 UTC, the attacker first used a compromised identity to introduce IDE persistence payloads to the keyv repository, and then shortly after published a new version of keyv containing their payload. This worm has since propagated to over 400 distinct npm packages.