🚨 Active supply chain attack on npm: keyv and cacheable are compromised right now, and the payload is a worm.
The maintainer account behind both package families was compromised. On August 4, ten packages were republished with a malicious preinstall hook that steals your credentials, then uses those credentials to publish itself into more packages. Malicious versions are live on npm as I write this.
These are foundational packages. keyv, cacheable, flat-cache, and file-entry-cache sit deep in dependency trees as transitive deps of common tooling like ESLint. Tens of millions of weekly downloads. Most affected users never installed them directly.
What the payload does:
• preinstall hook (setup.mjs) downloads a standalone Bun runtime and runs the second stage under it, sidestepping the host Node version and any Node-level monitoring
• Harvests cloud and CI credentials: AWS/GCP/Azure keys, HashiCorp Vault tokens, Kubernetes service account tokens, GitHub Actions OIDC, and npm tokens
• Repackages other npm packages with the same hook and republishes them through npm OIDC trusted publishing. This is what makes it a worm.
• Exfiltrates over DNS and by committing stolen secrets to attacker-created GitHub repos
• Plants autostart hooks in .claude and .vscode that execute when a developer or an AI coding agent opens the cloned repo. No npm install required.
The detail worth sitting with: keyv@6.0.0 shipped with a passing npm provenance attestation. The build pipeline faithfully attested a source that was already trojanized. Signature verification alone did not stop this.
Socket’s AI scanner flagged the malicious setup.mjs hook. If you install anything in the keyv, @keyv, or cacheable scopes:
• Pin to the last known-clean version and rebuild lockfiles by integrity hash. No caret or tilde ranges, no npm update.
• Better: block the entire keyv, @keyv, and cacheable scope at your registry proxy until the account is confirmed clean.
• Rotate and revoke every credential reachable from any host that ran install scripts. npm and GitHub tokens should be revoked, not just rotated.
Developing story. Socket is updating the affected-package list as new versions appear.
Full research report with IoCs:
socket.dev/blog/popular-npm-…
If you are dealing with this right now and want help, email sales@socket.dev and we will spin up emergency white-glove assistance.