Keyv and Cacheable npm Packages Compromised in Active Supply-Chain Attack
Blog post from Cloudsmith
On August 4, 2026, a self-propagating worm initiated a supply-chain attack targeting npm packages, particularly keyv and cacheable, marking the event as keyv-shai-hulud. The attack involved the publication of 2,236 malicious versions across 444 legitimate packages, exploiting their deep integration into JavaScript dependency graphs. This attack was characterized by its rapid spread, facilitated by lifecycle scripts that executed harmful payloads to harvest credentials and propagate further. Organizations using npm v12 or later, which disables lifecycle scripts by default, have a degree of protection, while those on older versions or with scripts enabled remain vulnerable. To assess exposure, organizations must review lockfiles and package versions, ensuring they match updated community trackers, and confirm whether lifecycle scripts could execute in their environments. Cloudsmith offers a preventative measure by acting as an intermediary between public registries and developers, enforcing cooldown and malware policies that delay the availability of new versions and block those identified as malicious, thereby reducing the risk of such supply chain attacks.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 1 | 584 | 99 | 52 | -76% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.