Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
2,073
Company Posts That Month
1
Language
English
Hacker News Points
-
Post removed?
No
Summary

Socket's Threat Research Team has identified an active supply chain attack impacting keyv and cacheable npm packages, with a malicious preinstall hook that exploits cloud and CI credentials, allowing the distribution of compromised packages. The attack, initiated by a breach of maintainer Jaredwray's account, uses a setup.mjs script to download a Bun runtime, execute a second stage, and republish trojanized packages, affecting millions of downloads. The compromise targets secrets across AWS, GCP, Azure, and other services, and self-propagates by infecting additional packages using stolen npm tokens. The threat actor utilizes GitHub for data exfiltration and employs autostart hooks to trigger payloads when developers clone repositories. Socket's AI scanner detected the malicious activity within minutes of the initial publication, and the investigation is ongoing. The incident highlights the need for developers and security teams to pin package versions, rotate credentials, and remove potential persistence mechanisms to mitigate the impact.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.