The keyv and cacheable npm Supply Chain Worm
Updated 5 Oct 2026 · Incident date 4 Aug 2026 · npm
keyv 5.x -> 6.0.0, cacheable 2.5.1, cacheable-request 13.0.20, flat-cache 6.1.24, file-entry-cache 11.1.7 (1,300+ poisoned versions)setup.mjsOn 4 August 2026 attackers published poisoned versions of keyv 6.0.0, cacheable 2.5.1, cacheable-request 13.0.20, flat-cache 6.1.24 and file-entry-cache 11.1.7 to npm. Aikido calls this a Shai-Hulud style worm. It also spread to hundreds of other packages.
A poisoned package ran code during npm install. The code stole cloud and login keys, then used stolen npm tokens to publish more poisoned packages.
What happened
A maintainer account for the keyv and cacheable packages was compromised on 4 August 2026, and the attacker published malicious versions to npm. Socket reports the first keyv 6.0.0 release at 09:35 UTC. A second burst in the cacheable namespace followed between 10:09 and 10:14 UTC.
Aikido reports that the attacker pushed malicious files straight to the main branch of the repository. The new releases then carried valid GitHub Actions signatures. Wiz says the malware belongs to the "Mini" Shai-Hulud family.
Each poisoned package added two files, setup.mjs and Math_Symbol.js, and a preinstall hook in package.json. The hook runs node setup.mjs. That script downloads a Bun runtime from GitHub and runs the second stage, a large obfuscated bundle.
The second stage collects secrets. Socket lists AWS, GCP and Azure credentials, HashiCorp Vault tokens, Kubernetes service account tokens, GitHub Actions OIDC tokens and npm tokens. Aikido adds roughly 200 file patterns for .env files, SSH keys, Terraform state and Docker configs.
The worm then looks up the packages the victim can publish, adds the same hook, and republishes them with stolen npm tokens. Aikido counts more than 440 packages and 1,381 versions in the secondary spread. The malware also writes persistence into .claude/settings.json and .vscode/tasks.json so it runs again when a developer opens the project.
The earlier keyv 5.x releases and 6.0.0-rc.1 were clean. The poisoned tarballs differ from them by two new executable files and the preinstall hook. This is the type of change Vigilance reports when it compares a trusted version with a new one.
Affected versions
The primary poisoned versions are listed below. Socket and Aikido list them. The full list is much longer, and Wiz publishes it in its IOC repository.
keyv@6.0.0cacheable@2.5.1cacheable-request@13.0.20flat-cache@6.1.24file-entry-cache@11.1.7(Socket). Aikido lists 11.1.6, so check both.@cacheable/memory@2.2.1,@cacheable/utils@2.5.1,@cacheable/net@2.1.1,@cacheable/node-cache@3.1.2cache-manager@7.2.10- Scoped
@keyv/*packages such as@keyv/redis,@keyv/sqliteand@keyv/mongo
Any other package that gained a new patch version on 4 August 2026 with a preinstall hook can also be a victim of the worm.
Indicators of compromise
These indicators come from Socket, Wiz and Aikido. Defang domains before you share them.
- Files:
setup.mjsandMath_Symbol.jsormath_init.jsinsidenode_modules - Hook in
package.json:"preinstall": "node setup.mjs" - SHA-256 of
setup.mjs:54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668 - SHA-256 of the community-spread
setup.mjs:fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb - SHA-256 of
Math_Symbol.js:9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc - Temporary folders
/tmp/bun-dl-*/ - Persistence:
~/.local/bin/gh-token-monitor.sh,~/.config/gh-token-monitor/,~/Library/LaunchAgents/com.user.gh-token-monitor.plist,~/.config/systemd/user/gh-token-monitor.service - Unexpected hooks in
~/.claude/settings.jsonand.vscode/tasks.json - Network:
npm-cache[.]comandeth-mainnet.nodereal[.]io, plus the user agentBun/1.3.13 - GitHub: public repositories with the description "Shai-Hulud: Here We Go Again", and commits by
claudewith the message "chore: update config"
How to check
You can search your projects and lockfiles for the bad versions and for the dropped files. These commands only read files and do not run any package.
npm ls keyv cacheable cacheable-request flat-cache file-entry-cache cache-manager
find . -path "*/node_modules/*" \( -name Math_Symbol.js -o -name math_init.js \) 2>/dev/null; ls -d /tmp/bun-dl-* 2>/dev/null
grep -rn "node setup.mjs" --include=package.json . 2>/dev/null
Also look for the persistence files listed above, and check your GitHub account for new repositories you did not create.
What to do now
- Remove the poisoned versions from developer machines, build agents and CI. Pin to the version before the bad one.
- If a bad version was installed, treat the machine as compromised.
- Remove the persistence files and the
bun-dl-*folders first. Socket warns that a dead-man switch watches your GitHub token. - Then revoke and replace npm tokens, GitHub tokens, cloud keys, Vault tokens and Kubernetes tokens.
- Check your npm account for versions you did not publish on 4 August 2026, and your GitHub account for new repositories and commits.
- Block the
keyv,@keyvandcacheablescopes in your registry proxy until the maintainers confirm clean releases.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 14 (2 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE setup.mjs It runs a command on its own when it is installed, downloads from the internet and reads saved passwords and access keys.
Frequently asked questions
What is the keyv npm supply chain attack?
On 4 August 2026 attackers used a compromised maintainer account to publish poisoned versions of keyv, cacheable and related npm packages. The code ran at install time, stole credentials and republished other packages.
Which keyv version is malicious?
keyv 6.0.0 is the poisoned release named by Socket, Wiz and Aikido. The 5.x releases and 6.0.0-rc.1 were clean.
How do I know if I installed a poisoned package?
Run npm ls for the affected packages and look in node_modules for Math_Symbol.js or math_init.js. Also look for a preinstall hook that runs node setup.mjs.
Sources
More supply chain attacks
- @apexacc/cli Defender-blinding C2 loader 17 Sept 2026
- Mastra AI npm compromise (Sapphire Sleet) 17 Jun 2026
- TanStack npm compromise (Mini Shai-Hulud) 11 May 2026
- axios npm maintainer account takeover 31 Mar 2026
All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.