Supply Chain Compromise: Malicious Code Found in Popular npm Packages Keyv and Cacheable
A significant supply chain compromise has been identified in the npm ecosystem, affecting the widely used keyv and cacheable packages. On August 4, 2026, malicious preinstall hooks were discovered in at least ten packages within these namespaces. The compromised packages, which include keyv@6.0.0, were found to contain a setup.mjs script that downloads a standalone Bun runtime, executes a second stage, and harvests cloud and CI credentials. The attack has led to the republishing of trojanized versions of other packages using stolen npm tokens. The maintainer account, identified as Jaredwray, was compromised, allowing the threat actor to publish across multiple package families. The attack has resulted in the theft of credentials from cloud services like AWS, GCP, and Azure, as well as GitHub and npm tokens. The malicious packages have been downloaded millions of times, posing a significant risk to developers and organizations relying on these dependencies.