socket.dev
Keyv and Cacheable npm Packages Compromised with Malicious Payloads
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On August 4, 2026, attackers compromised the release path for keyv and cacheable npm packages, publishing trojanized versions starting with [email protected]. The malicious packages included a preinstall hook that executed an obfuscated payload, Math_Symbol.js, which harvested sensitive credentials from cloud and CI environments. The attack leveraged passing npm provenance to bypass security checks, allowing the malware to propagate and infect other packages. Snyk identified 11 malicious releases, while socket.dev flagged [email protected] within six minutes of its release. The incident has critical operational severity, as it allows for code execution with developer privileges. Immediate remediation actions include isolating affected systems and rotating credentials. As of the latest update, eight malicious releases remain tagged as latest on npm.
Key Points: • Attackers compromised keyv and cacheable npm packages, publishing at least 11 malicious versions. • The malicious payload harvests sensitive credentials and can self-propagate to other packages. • Immediate action is required to isolate affected systems and rotate credentials.