What's Happening?
An active supply chain compromise has been identified affecting the widely used npm packages keyv and cacheable. The compromise involves a malicious preinstall hook that downloads a standalone Bun runtime, executes an obfuscated second stage, and harvests
cloud and CI credentials. The affected packages, published on August 4, 2026, account for tens of millions of weekly downloads. The maintainer account was compromised, allowing the publication of trojanized versions of additional packages. The payload exfiltrates sensitive data and republishes through the victim's npm identity, extending the campaign's reach.
Why It's Important?
This compromise poses a significant threat to developers and organizations relying on these npm packages. The ability to harvest cloud provider keys, Vault and Kubernetes tokens, and GitHub credentials can lead to unauthorized access and data breaches. The widespread use of these packages means that many systems could be vulnerable, potentially affecting a large number of applications and services. The incident highlights the critical need for robust security measures in software supply chains to prevent such attacks.
What's Next?
Developers and security teams are advised to treat any environment that installed an affected version as compromised. Immediate actions include pinning affected packages to safe versions, removing host-level persistence mechanisms, and rotating all credentials. Ongoing monitoring and updates from security teams like Socket are crucial to mitigate the impact and prevent further exploitation. The incident underscores the importance of continuous vigilance and proactive security practices in software development.











