Active npm Supply Chain Attack: keyv and Core Packages Hit by Credential-Stealing Worm
DanielLockyer · x · 2026-08-04
A severe supply chain attack is hitting the npm ecosystem, compromising foundational packages like keyv and cacheable with tens of millions of weekly downloads. Attackers compromised a maintainer account to publish versions with a malicious preinstall hook.
The payload acts as a worm, downloading an obfuscated script to steal AWS/GCP/Azure cloud credentials, Kubernetes tokens, and npm tokens. It then uses these tokens to propagate itself into more packages. Since these are often deep transitive dependencies of common tools like ESLint, many developers could be affected unknowingly.
More from coding & agent
- Not Diamond Code Launches: Intelligent Model Router for Coding Agents — damianplayer · 2026-08-05
- Cloudflare Uses AI Software Factory to Drive Astro's Open Issues to Zero — irvinebroque · 2026-08-05
- Developer Calls for a 'Do Not Disturb' Mode for AI Coding Agents — haltakov · 2026-08-05
- NVIDIA Tutorial: Build NemoClaw Agents on Jetson Platform — NVIDIAAI · 2026-08-05
- Agentic RL Bottlenecked by Inference: SkyPilot Halves Training Time — skypilot_org · 2026-08-05
- Tutorial: How to connect your AI agents to Slack for better team collaboration — pritisinghhhh · 2026-08-04