


Perceptive Security
SOC/SIEM Consultancy

Popular npm packages keyv and cacheable compromised.
Published:
4 August 2026 at 10:36:00
Alert date:
4 August 2026 at 12:01:53
Source:
socket.dev
Supply Chain & Dependencies, Ransomware & Malware, Data Breach & Exfiltration, Identity & Access, Web Technologies
On August 4, 2026, the maintainer account 'Jaredwray' was compromised, leading to the publication of malicious versions of at least ten npm packages including keyv and cacheable. The attack used a preinstall hook (setup.mjs) that downloads a standalone Bun runtime and executes an obfuscated second-stage payload (Math_Symbol.js). The payload harvests cloud and CI credentials including AWS, GCP, Azure, HashiCorp Vault, Kubernetes tokens, GitHub Actions OIDC, and npm tokens. The malware self-propagates by republishing trojanized versions of other packages the stolen npm token can reach, functioning as a worm. Exfiltration occurs via GitHub repositories created through the API and DNS channels. Persistence is achieved by planting autostart hooks in .claude/settings.json and .vscode/tasks.json. The tradecraft closely matches the Shai-Hulud npm worm campaign. Affected packages have tens of millions of weekly downloads and are transitive dependencies of tools like ESLint. All credentials reachable from affected environments should be rotated immediately.
Technical details
Mitigation steps:
Affected products:
keyv@6.0.0
cacheable@2.5.1
cacheable-request@13.0.20
flat-cache@6.1.24
@cacheable/net@2.1.1
@cacheable/node-cache@3.1.2
@cacheable/memory@2.2.1
cache-manager@7.2.10
@thiennq/docs-viewer@1.6.2
file-entry-cache@11.1.6
@cacheable/utils@2.5.1
Related links:
https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain?utm_medium=feed
https://socket.dev/npm/package/keyv/files/6.0.0/package.json
https://socket.dev/npm/package/keyv/files/6.0.0/setup.mjs
https://www.npmjs.com/package/keyv/v/6.0.0
https://www.npmjs.com/package/cacheable/v/2.5.1
https://www.npmjs.com/package/cacheable-request/v/13.0.20
https://www.npmjs.com/package/flat-cache/v/6.1.24
https://www.npmjs.com/package/@cacheable/net/v/2.1.1
https://www.npmjs.com/package/@cacheable/node-cache/v/3.1.2
https://www.npmjs.com/package/@cacheable/memory/v/2.2.1
https://socket.dev/npm/package/cache-manager/overview/7.2.10
https://socket.dev/npm/package/@thiennq/docs-viewer/overview/1.6.2
https://socket.dev/npm/package/file-entry-cache
https://socket.dev/npm/package/@cacheable/utils/overview/2.5.1
Related CVE's:
Related threat actors:
IOC's:
fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb, 54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668, 9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc, 169.254.169.254, 169.254.170.2, github.com/oven-sh/bun/releases/download/bun-v1.3.13/, registry.npmjs.org/-/whoami, registry.npmjs.org/-/npm/v1/tokens, registry.npmjs.org/-/npm/v1/oidc/token/exchange/package/, setup.mjs, Math_Symbol.js, math_init.js
This article was created with the assistance of AI technology by Perceptive.
