NPM Malware Compromises keyv and cacheable with 500M+ Weekly Downloads and Spreads to Hundreds of Packages
Blog post from Endor Labs
A sophisticated malware campaign has compromised the npm ecosystem, targeting packages under the jaredwray/Cacheable ecosystem and spreading to others through stolen npm publishing tokens. Initially, malicious versions were published via a legitimate GitHub Actions pipeline, affecting widely-used packages like keyv, flat-cache, and file-entry-cache, which collectively account for around 515 million weekly downloads. The attack has since extended to packages maintained by reputable companies, leveraging stolen tokens to publish malicious versions under their namespaces. The malware utilizes a setup.mjs script to download and execute an obfuscated payload, targeting AWS credentials, npm tokens, GitHub tokens, and HashiCorp Vault tokens. The campaign's reach is extensive, with 1,136 verified malicious versions across 384 packages, and the list continues to grow. Users are advised to pin or roll back affected packages to pre-compromise versions, check lockfiles and CI logs for malicious versions, and rotate credentials on compromised systems. Endor Labs is actively monitoring the situation and plans to provide a comprehensive technical analysis in a future update.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 3 | 584 | 99 | 52 | -76% |
| Serverless | 3 | 149 | 44 | 30 | -80% |
| MCP | 2 | 1,562 | 186 | 99 | -80% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.