Keyv npm Package Compromised in Major Supply Chain Attack

On August 4, 2026, attackers compromised the GitHub account of the maintainer behind Keyv, a widely-used key-value storage library with approximately 127 million weekly downloads on npm. This breach led to the distribution of credential-stealing malware across the maintainer’s entire package portfolio, marking one of the most significant npm supply chain incidents to date.

The compromised maintainer also oversees several other popular caching utilities, including Cacheable (29 million downloads monthly), Flat-Cache (565 million downloads monthly), File-Entry-Cache (557 million downloads monthly), Cache-Manager, Cacheable-Request, and the @cacheable scoped packages. All these packages were affected by the attack.

The attackers injected malicious files directly into each repository’s main branch and promptly released new versions. These versions were published to npm with valid provenance signatures generated by GitHub Actions, making them appear legitimate to those auditing supply chain integrity.

Mechanism of the Attack

Each affected package received two new files: setup.mjs and Math_Symbol.js. Additionally, a “preinstall” hook was added to the package.json file, ensuring that setup.mjs executes automatically during the npm install process.

When triggered, setup.mjs acts as an obfuscated dropper that downloads the Bun JavaScript runtime from a GitHub release URL and uses it to execute Math_Symbol.js without alerting the developer. This self-propagating design enabled the malware, identified as part of the Shai-Hulud campaign, to extend beyond the original maintainer’s packages and infect codebases of major organizations, including Deliveroo, Qlik, and Picsart.

As of 13:20 CEST on August 4, at least 868 packages across 1,381 versions had been confirmed compromised, with the number continuing to rise as researchers monitor the ongoing spread within the registry.

Malware Capabilities

The Math_Symbol.js payload is designed to extract various credentials from developer machines and CI/CD environments. It targets:

  • npm registry authentication tokens from .npmrc files
  • GitHub CLI tokens, including personal access tokens, session tokens, and OIDC tokens from local GitHub CLI configurations
  • AWS access keys and session tokens from the ~/.aws/credentials file
  • HashiCorp Vault client tokens via the VAULT_TOKEN environment variable, with a fallback mechanism to retrieve a token over HTTP if the environment variable is absent

These credentials are crucial for publishing new packages and accessing cloud infrastructure. A single successful theft can lead to further account takeovers and additional malicious releases, facilitating the worm’s continued propagation across the npm ecosystem.

Recommended Actions

Teams relying on Keyv, Cacheable, Flat-Cache, File-Entry-Cache, or related caching packages should immediately:

  • Audit their lockfiles for affected versions
  • Rotate npm tokens, GitHub CLI credentials, AWS keys, and Vault tokens on any machine that executed an install during the exposure window
  • Avoid running fresh installs against affected dependency trees until patched versions are confirmed

Given the scale and speed of this compromise, security teams should treat any recent CI pipeline run involving these packages as potentially exposed.

This incident underscores the critical need for robust security practices in managing open-source dependencies. Developers and organizations must implement stringent access controls, regularly audit their packages, and stay vigilant against emerging threats to safeguard their software supply chains.