August 2026 Summaries
1 posts from Socket
Filter
Month:
Year:
Post Summaries
Back to Blog
Socket's Threat Research Team has identified an active supply chain attack impacting keyv and cacheable npm packages, with a malicious preinstall hook that exploits cloud and CI credentials, allowing the distribution of compromised packages. The attack, initiated by a breach of maintainer Jaredwray's account, uses a setup.mjs script to download a Bun runtime, execute a second stage, and republish trojanized packages, affecting millions of downloads. The compromise targets secrets across AWS, GCP, Azure, and other services, and self-propagates by infecting additional packages using stolen npm tokens. The threat actor utilizes GitHub for data exfiltration and employs autostart hooks to trigger payloads when developers clone repositories. Socket's AI scanner detected the malicious activity within minutes of the initial publication, and the investigation is ongoing. The incident highlights the need for developers and security teams to pin package versions, rotate credentials, and remove potential persistence mechanisms to mitigate the impact.
Aug 04, 2026
2,073 words in the original blog post.