top of page
perceptive_background_267k.jpg

Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)

Published:

5 August 2026 at 19:53:03

Alert date:

5 August 2026 at 20:03:16

Source:

isc.sans.edu

Click to open the original link from this advisory

Supply Chain & Dependencies, Ransomware & Malware, Identity & Access

A supply chain attack targeting the popular npm packages keyv and cacheable has been unfolding, involving a compromised package that executes malicious code on build hosts. The attack has an unusual and dangerous characteristic: revoking the stolen npm token or rotating credentials is the trigger that arms the payload, inverting the normal incident response reflex. This means that standard security responses such as revoking npm tokens, rotating GitHub PATs, and cycling cloud keys could make the situation worse. Security teams that learned of a compromised build host are warned not to revoke tokens immediately. The incident highlights the sophistication of modern supply chain attacks, where attackers anticipate and weaponize defender responses. This represents a significant threat to CI/CD pipelines and software build infrastructure across organizations using these widely-adopted npm packages.

Technical details

Mitigation steps:

Affected products:

keyv
cacheable
npm

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page