


Perceptive Security
SOC/SIEM Consultancy

Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)
Published:
5 augustus 2026 om 17:53:03
Alert date:
5 augustus 2026 om 18:03:16
Source:
isc.sans.edu
Supply Chain & Dependencies, Ransomware & Malware, Identity & Access
A supply chain attack targeting the popular npm packages keyv and cacheable has been unfolding, involving a compromised package that executes malicious code on build hosts. The attack has an unusual and dangerous characteristic: revoking the stolen npm token or rotating credentials is the trigger that arms the payload, inverting the normal incident response reflex. This means that standard security responses such as revoking npm tokens, rotating GitHub PATs, and cycling cloud keys could make the situation worse. Security teams that learned of a compromised build host are warned not to revoke tokens immediately. The incident highlights the sophistication of modern supply chain attacks, where attackers anticipate and weaponize defender responses. This represents a significant threat to CI/CD pipelines and software build infrastructure across organizations using these widely-adopted npm packages.
Technical details
Mitigation steps:
Affected products:
keyv
cacheable
npm
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
