The keyv and cacheable npm Supply Chain Worm

Updated 5 Oct 2026 · Incident date 4 Aug 2026 · npm

Packagekeyv 5.x -> 6.0.0, cacheable 2.5.1, cacheable-request 13.0.20, flat-cache 6.1.24, file-entry-cache 11.1.7 (1,300+ poisoned versions)
Filesetup.mjs

On 4 August 2026 attackers published poisoned versions of keyv 6.0.0, cacheable 2.5.1, cacheable-request 13.0.20, flat-cache 6.1.24 and file-entry-cache 11.1.7 to npm. Aikido calls this a Shai-Hulud style worm. It also spread to hundreds of other packages.

A poisoned package ran code during npm install. The code stole cloud and login keys, then used stolen npm tokens to publish more poisoned packages.

What happened

A maintainer account for the keyv and cacheable packages was compromised on 4 August 2026, and the attacker published malicious versions to npm. Socket reports the first keyv 6.0.0 release at 09:35 UTC. A second burst in the cacheable namespace followed between 10:09 and 10:14 UTC.

Aikido reports that the attacker pushed malicious files straight to the main branch of the repository. The new releases then carried valid GitHub Actions signatures. Wiz says the malware belongs to the "Mini" Shai-Hulud family.

Each poisoned package added two files, setup.mjs and Math_Symbol.js, and a preinstall hook in package.json. The hook runs node setup.mjs. That script downloads a Bun runtime from GitHub and runs the second stage, a large obfuscated bundle.

The second stage collects secrets. Socket lists AWS, GCP and Azure credentials, HashiCorp Vault tokens, Kubernetes service account tokens, GitHub Actions OIDC tokens and npm tokens. Aikido adds roughly 200 file patterns for .env files, SSH keys, Terraform state and Docker configs.

The worm then looks up the packages the victim can publish, adds the same hook, and republishes them with stolen npm tokens. Aikido counts more than 440 packages and 1,381 versions in the secondary spread. The malware also writes persistence into .claude/settings.json and .vscode/tasks.json so it runs again when a developer opens the project.

The earlier keyv 5.x releases and 6.0.0-rc.1 were clean. The poisoned tarballs differ from them by two new executable files and the preinstall hook. This is the type of change Vigilance reports when it compares a trusted version with a new one.

Affected versions

The primary poisoned versions are listed below. Socket and Aikido list them. The full list is much longer, and Wiz publishes it in its IOC repository.

Any other package that gained a new patch version on 4 August 2026 with a preinstall hook can also be a victim of the worm.

Indicators of compromise

These indicators come from Socket, Wiz and Aikido. Defang domains before you share them.

How to check

You can search your projects and lockfiles for the bad versions and for the dropped files. These commands only read files and do not run any package.

npm ls keyv cacheable cacheable-request flat-cache file-entry-cache cache-manager
find . -path "*/node_modules/*" \( -name Math_Symbol.js -o -name math_init.js \) 2>/dev/null; ls -d /tmp/bun-dl-* 2>/dev/null
grep -rn "node setup.mjs" --include=package.json . 2>/dev/null

Also look for the persistence files listed above, and check your GitHub account for new repositories you did not create.

What to do now

  1. Remove the poisoned versions from developer machines, build agents and CI. Pin to the version before the bad one.
  2. If a bad version was installed, treat the machine as compromised.
  3. Remove the persistence files and the bun-dl-* folders first. Socket warns that a dead-man switch watches your GitHub token.
  4. Then revoke and replace npm tokens, GitHub tokens, cloud keys, Vault tokens and Kubernetes tokens.
  5. Check your npm account for versions you did not publish on 4 August 2026, and your GitHub account for new repositories and commits.
  6. Block the keyv, @keyv and cacheable scopes in your registry proxy until the maintainers confirm clean releases.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old keyv-5.x --new keyv-6.0.0
files scanned: 14 (2 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   setup.mjs
           It runs a command on its own when it is installed, downloads from the internet and reads saved passwords and access keys.

Frequently asked questions

What is the keyv npm supply chain attack?

On 4 August 2026 attackers used a compromised maintainer account to publish poisoned versions of keyv, cacheable and related npm packages. The code ran at install time, stole credentials and republished other packages.

Which keyv version is malicious?

keyv 6.0.0 is the poisoned release named by Socket, Wiz and Aikido. The 5.x releases and 6.0.0-rc.1 were clean.

How do I know if I installed a poisoned package?

Run npm ls for the affected packages and look in node_modules for Math_Symbol.js or math_init.js. Also look for a preinstall hook that runs node setup.mjs.

Sources

  1. socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain
  2. wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack
  3. aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack

More supply chain attacks

All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free