top of page
perceptive_background_267k.jpg

Popular npm packages keyv and cacheable compromised.

Published:

4 August 2026 at 10:36:00

Alert date:

4 August 2026 at 12:01:53

Source:

socket.dev

Click to open the original link from this advisory

Supply Chain & Dependencies, Ransomware & Malware, Data Breach & Exfiltration, Identity & Access, Web Technologies

On August 4, 2026, the maintainer account 'Jaredwray' was compromised, leading to the publication of malicious versions of at least ten npm packages including keyv and cacheable. The attack used a preinstall hook (setup.mjs) that downloads a standalone Bun runtime and executes an obfuscated second-stage payload (Math_Symbol.js). The payload harvests cloud and CI credentials including AWS, GCP, Azure, HashiCorp Vault, Kubernetes tokens, GitHub Actions OIDC, and npm tokens. The malware self-propagates by republishing trojanized versions of other packages the stolen npm token can reach, functioning as a worm. Exfiltration occurs via GitHub repositories created through the API and DNS channels. Persistence is achieved by planting autostart hooks in .claude/settings.json and .vscode/tasks.json. The tradecraft closely matches the Shai-Hulud npm worm campaign. Affected packages have tens of millions of weekly downloads and are transitive dependencies of tools like ESLint. All credentials reachable from affected environments should be rotated immediately.

Technical details

Mitigation steps:

Affected products:

keyv@6.0.0
cacheable@2.5.1
cacheable-request@13.0.20
flat-cache@6.1.24
@cacheable/net@2.1.1
@cacheable/node-cache@3.1.2
@cacheable/memory@2.2.1
cache-manager@7.2.10
@thiennq/docs-viewer@1.6.2
file-entry-cache@11.1.6
@cacheable/utils@2.5.1

Related links:

Related CVE's:

Related threat actors:

IOC's:

fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb, 54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668, 9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc, 169.254.169.254, 169.254.170.2, github.com/oven-sh/bun/releases/download/bun-v1.3.13/, registry.npmjs.org/-/whoami, registry.npmjs.org/-/npm/v1/tokens, registry.npmjs.org/-/npm/v1/oidc/token/exchange/package/, setup.mjs, Math_Symbol.js, math_init.js

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page