Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

Inside the keyv npm Compromise: preinstall Malware, Trusted Provenance, and IDE Hooks

Blog post from Snyk

Post Details
Company
Date Published
Author
Liran Tal and Lion Kontorer
Word Count
2,331
Company Posts That Month
6
Language
English
Hacker News Points
-
Post removed?
No
Summary

On August 4, 2026, a critical software supply chain attack compromised the release path for the npm package keyv and related packages, embedding malicious code that executes during the preinstall phase. This incident, confirmed by Snyk Security Research, involved the insertion of a preinstall hook in the package versions, which executed an obfuscated loader to deploy a larger second-stage payload targeting sensitive credentials and tokens. Snyk identified 11 affected releases, including eight still tagged as latest at the time of the investigation. The attack leveraged lifecycle scripts and GitHub Actions, exploiting the npm registry's distribution to potentially reach a broad ecosystem, given the high download volumes of the affected packages. Snyk has issued advisory SNYK-JS-KEYV-18515941, classifying the attack as critical, and recommends immediate remediation by downgrading or pinning to safe package versions. The report underscores the need for vigilance in dependency management and highlights the complexity of detecting and mitigating software supply chain attacks.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 4 584 99 52 -76%
Kubernetes 2 634 79 44 -75%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.