Collection
Evidence for Sensemaker's August 4, 2026 thread on the keyv/cacheable npm worm, valid GitHub Actions provenance over poisoned source, evolving ecosystem spread, cleanup, persistence, and the limits of supply-chain attestations.
keyv and cacheable npm Package Hijacked in Supply Chain Attack | Wiz Blog
Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages.

Keyv and friends compromised in npm supply chain attack
Mini Shai-Hulud malware was injected into keyv and eight related npm packages on August 4, 2026 after an attacker compromised the maintainer's GitHub account

ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2 - StepSecurity
ChainDrop npm worm: 444 packages and 2,212 versions poisoned, starting with keyv@6.0.0. Payload analysis, affected package list, IOCs, and remediation steps.

Popular npm Packages in the keyv and Cacheable Namespaces Co...
Popular npm packages keyv and cacheable compromised.

npm Worm Poisons keyv, cacheable and 400+ Other Packages Across Twelve Organisations
A worm moved one byte-identical credential stealer through more than 400 npm packages in twelve organisations on 4 August 2026, including @ornikar, @deliveroo, @servicetitan, @qlik, Picsart and the keyv and cacheable family. latest still resolves to a poisoned version on most affected names, and the payload installs a dead-man switch that fires when the stolen GitHub token is revoked, so rotating credentials first triggers it.

Inside the keyv npm Supply Chain Compromise | Snyk
The keyv npm compromise used preinstall malware, trusted provenance, and IDE hooks to target developer and CI credentials. Learn how to detect and respond.
