Supply Chain Compromise: Popular npm Packages Keyv and Cacheable Affected
Trendline

Supply Chain Compromise: Popular npm Packages Keyv and Cacheable Affected

What's Happening? An active supply chain compromise has been identified affecting the widely used npm packages keyv and cacheable. The compromise involves a malicious preinstall hook that downloads a standalone Bun runtime, executes an obfuscated second stage, and harvests cloud and CI credentials.
AI Generated
This may include content generated using AI tools. Glance teams are making active and commercially reasonable efforts to moderate all AI generated content. Glance moderation processes are improving however our processes are carried out on a best-effort basis and may not be exhaustive in nature. Glance encourage our users to consume the content judiciously and rely on their own research for accuracy of facts. Glance maintains that all AI generated content here is for entertainment purposes only.