Keyv and Cacheable npm Packages Compromised with Malicious Payloads

Keyv and Cacheable npm Packages Compromised with Malicious Payloads

First seen 4 Aug 2026, 16:28 UTC Snyksocket.dev 76% similarity 69.9

Article Content

Browse articles
ThreatCluster

On August 4, 2026, attackers compromised the release path for keyv and cacheable npm packages, publishing trojanized versions starting with [email protected]. The malicious packages included a preinstall hook that executed an obfuscated payload, Math_Symbol.js, which harvested sensitive credentials from cloud and CI environments. The attack leveraged passing npm provenance to bypass security checks, allowing the malware to propagate and infect other packages. Snyk identified 11 malicious releases, while socket.dev flagged [email protected] within six minutes of its release. The incident has critical operational severity, as it allows for code execution with developer privileges. Immediate remediation actions include isolating affected systems and rotating credentials. As of the latest update, eight malicious releases remain tagged as latest on npm.

Key Points: • Attackers compromised keyv and cacheable npm packages, publishing at least 11 malicious versions. • The malicious payload harvests sensitive credentials and can self-propagate to other packages. • Immediate action is required to isolate affected systems and rotate credentials.

ThreatCluster AI How this analysis works

Timeline

2026-08-04
Keyv and cacheable packages compromised
Attackers published trojanized versions of keyv and cacheable packages, starting with [email protected] at 09:35 UTC.
socket.dev
2026-08-04
Snyk identifies malicious releases
Snyk found 11 malicious releases across keyv and related packages, with eight still tagged as latest at 11:16 UTC.
Snyk
2026-08-04
Socket flags [email protected]
Socket.dev flagged the malicious [email protected] within six minutes of its publication, indicating rapid detection.
socket.dev

Community

Browse all →