Active npm Supply Chain Attack: keyv and Core Packages Hit by Credential-Stealing Worm

DanielLockyer · x · 2026-08-04

A severe supply chain attack is hitting the npm ecosystem, compromising foundational packages like keyv and cacheable with tens of millions of weekly downloads. Attackers compromised a maintainer account to publish versions with a malicious preinstall hook.

The payload acts as a worm, downloading an obfuscated script to steal AWS/GCP/Azure cloud credentials, Kubernetes tokens, and npm tokens. It then uses these tokens to propagate itself into more packages. Since these are often deep transitive dependencies of common tools like ESLint, many developers could be affected unknowingly.

Related event: npm Supply Chain Attack: 868 Packages Infected with Credential-Stealing Worm(3 posts)→

Original post →

More from coding & agent

coding & agent channel →