Active npm Supply-Chain Attack Compromises Keyv and Cacheable Packages

· Original article ↗

Summary

A malicious npm preinstall hook in Keyv, Cacheable, and other packages steals developer and CI credentials, spreads by republishing trojanized packages, and installs persistence. The investigation remains ongoing.

Key points

  • On August 4, 2026, at least ten packages across the Keyv and Cacheable ecosystems—and packages from other maintainers—were published with a malicious preinstall hook.
  • The loader downloads a standalone Bun runtime to execute an obfuscated payload that harvests cloud, Vault, Kubernetes, GitHub, npm, and CI credentials.
  • Using stolen credentials and npm OIDC trusted publishing, the payload can inject itself into other packages and publish trojanized versions.
  • The malware exfiltrates encrypted data through GitHub repositories and DNS-resolved destinations, and can install persistent services that react to token revocation.
  • Repository hooks in .claude and .vscode can trigger the loader when a developer or AI coding agent opens a cloned repository, without an npm install.
  • Treat environments that installed affected versions and ran install scripts as compromised; remove the persistence and implant before revoking or rotating exposed credentials.
  • Socket says the investigation and affected-package list are ongoing; the report notes that valid provenance can attest a build made from already-trojanized source.

Article Details

Attack Vectors
  • On 2026-08-04, a reportedly compromised Jaredwray maintainer account was used to publish keyv@6.0.0 with a malicious npm preinstall hook. The affected packages named in the article also include @thiennq/docs-viewer@1.6.2 and nine cacheable-family releases.
  • The preinstall hook runs setup.mjs, which downloads a standalone Bun runtime when needed and uses it to execute the obfuscated Math_Symbol.js payload.
  • The payload collects credentials from cloud instance metadata, files, environment variables, processes, and the npm registry. It can inject its hook into other packages accessible with stolen npm credentials and republish them.
  • Stolen findings are committed to threat actor-controlled GitHub repositories or sent encrypted to DNS-resolved destinations. Repository hooks in .claude/settings.json and .vscode/tasks.json can run the loader when a cloned repository is opened, without an npm install.
  • A host-level token watcher persists through a macOS LaunchAgent or Linux systemd user service. If the stolen GitHub token receives an HTTP 4xx response, the watcher evaluates a remote-supplied handler.
Defensive Notes
  • Treat environments that installed an affected version with install scripts enabled as compromised. Pin affected packages to earlier versions, rebuild lockfiles, and use exact versions and integrity hashes; consider blocking the affected namespaces while the maintainer account remains compromised.
  • Find and remove the token watcher, its LaunchAgent or systemd service, the loader and payload files, and the .claude and .vscode autostart hooks before revoking or rotating credentials. Token revocation can trigger the watcher's handler.
  • After removal, revoke affected npm and GitHub tokens, rotate other credentials reachable from the host, and audit npm accounts for unexpected releases and GitHub accounts for new repositories or unexpected commits.
  • A passing provenance attestation did not establish that keyv@6.0.0 was safe: the legitimate release workflow built already-trojanized source.

Indicators of compromise

TypeIndicatorContext
SHA25654dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668Hash of the malicious setup.mjs npm tarball preinstall loader.
SHA2569fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bccHash of the malicious second-stage payload, named Math_Symbol.js in the npm tarball and math_init.js in the repository.
SHA256fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1ebHash of the malicious setup.mjs repository loader used in .claude and .vscode.

MITRE ATT&CK

T1027 · Obfuscated Files or InformationThe second-stage bundle protects strings with polymorphic basE91 encoding and decodes them at runtime.T1059.007 · JavaScriptThe npm preinstall script runs the JavaScript loader setup.mjs, which launches the JavaScript second stage.T1105 · Ingress Tool TransferThe loader downloads a standalone Bun runtime before executing the second-stage payload.T1195.001 · Compromise Software Dependencies and Development ToolsTrojanized npm package releases carried a malicious preinstall hook into downstream installations.T1528 · Steal Application Access TokenThe payload steals npm and GitHub tokens and uses accessible npm credentials to republish packages.T1543.001 · Launch AgentThe payload persists its token watcher as a macOS LaunchAgent configured with RunAtLoad and KeepAlive.T1543.002 · Systemd ServiceThe payload persists its token watcher as a Linux systemd user service and enables lingering so it survives logout.T1546 · Event Triggered ExecutionHooks in .claude/settings.json and .vscode/tasks.json execute the loader when a cloned repository is opened.T1552.001 · Credentials In FilesThe payload searches files for secrets, including Vault tokens and Kubernetes service account tokens.T1552.005 · Cloud Instance Metadata APIThe collector queries cloud instance metadata, including AWS credential endpoints.T1567.001 · Exfiltration to Code RepositoryA payload component creates threat actor-controlled GitHub repositories and commits encrypted stolen findings to them.

Malware

Vendors

Products

@cacheable/memory@cacheable/node-cache@3.1.2, cacheable@2.5.1, flat-cache@6.1.24, cacheable-request@13.0.20, @cacheable/memory@2.2.1, file-entry-cache@11.1.6, @cacheable/utils@2.5.1, and cache-manager@7.2.10.@cacheable/netThe cacheable family published in a burst between 10:09:44 and 10:14:41: @cacheable/net@2.1.1, @cacheable/node-cache@3.1.2, cacheable@2.5.1, flat-cache@6.1.24, cacheable-request@13.0.20, @cacheable/memory@2.2.1,@cacheable/node-cacheThe cacheable family published in a burst between 10:09:44 and 10:14:41: @cacheable/net@2.1.1, @cacheable/node-cache@3.1.2, cacheable@2.5.1, flat-cache@6.1.24, cacheable-request@13.0.20, @cacheable/memory@2.2.1,@cacheable/utilsflat-cache@6.1.24, cacheable-request@13.0.20, @cacheable/memory@2.2.1, file-entry-cache@11.1.6, @cacheable/utils@2.5.1, and cache-manager@7.2.10.@thiennq/docs-viewer@thiennq/docs-viewer@1.6.2, a package outside the keyv and cacheable namespaces, published at 09:38, indicating the campaign reached at least one account beyond these two families.Bunother maintainers, were published with a malicious preinstall hook (setup.mjs) that downloads a standalone Bun runtime, executes an obfuscated second stage, harvests cloud and CI credentials, and republishes trojanizedcache-manager@cacheable/memory@2.2.1, file-entry-cache@11.1.6, @cacheable/utils@2.5.1, and cache-manager@7.2.10.cacheableThreat Research Team is tracking an active supply chain compromise affecting the widely used keyv and cacheable npm packages. On August 4, 2026, at least ten packages beginning with the keyv and cacheable namespacescacheable-requestcacheable, cacheable-request, flat-cache, and file-entry-cache are caching libraries in the same maintainer's ecosystem. These are foundational packages that sit deep in dependency trees, so their reach is largelyfile-entry-cachecacheable, cacheable-request, flat-cache, and file-entry-cache are caching libraries in the same maintainer's ecosystem. These are foundational packages that sit deep in dependency trees, so their reach is largelyflat-cachecacheable, cacheable-request, flat-cache, and file-entry-cache are caching libraries in the same maintainer's ecosystem. These are foundational packages that sit deep in dependency trees, so their reach is largelyGitHub ActionsCredential theft: cloud instance metadata, AWS/GCP/Azure keys, HashiCorp Vault, Kubernetes service account tokens, GitHub Actions OIDC, and npm tokens.keyvSocket’s Threat Research Team is tracking an active supply chain compromise affecting the widely used keyv and cacheable npm packages. On August 4, 2026, at least ten packages beginning with the keyv and cacheablenpmResearch Team is tracking an active supply chain compromise affecting the widely used keyv and cacheable npm packages. On August 4, 2026, at least ten packages beginning with the keyv and cacheable namespaces and

Related Articles