Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

A Devastating Supply Chain Attack: A Comprehensive Analysis of the Keyv-Linked npm Worm


A recent supply chain attack has left many organizations reeling as a credential-stealing npm worm spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations. The attack, which first appeared in keyv@6.0.0, utilized a preinstall script to run a credential-stealing bundle inside developer and continuous integration (CI) environments. To mitigate the impact of this devastating supply chain attack, SafeDep advises responders to remove the malware's credential-revocation watcher before rotating exposed tokens and keys.

  • A recent npm worm spread across hundreds of packages, compromising repository, package registry, cloud, and private-key material.
  • The worm's payload analysis revealed it could harvest data from GitHub, npm, cloud, Vault, Kubernetes, database, and private-key material.
  • The attack used OpenID Connect (OIDC) and Supply-chain Levels for Software Artifacts (SLSA) provenance to appear legitimate.
  • The worm was able to install a token-revocation watcher and carry npm publishing machinery, making it difficult to track.
  • The attack has significant implications for organizations relying on third-party libraries and dependencies.



  • A recent supply chain attack has left many organizations reeling, as a credential-stealing npm worm spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations. The attack, which first appeared in keyv@6.0.0, utilized a preinstall script to run a credential-stealing bundle inside developer and continuous integration (CI) environments. This malicious release not only harvested repository, package registry, cloud, and private-key material but also used available npm publishing access to poison more packages.

    The worm's payload analysis revealed that it could harvest GitHub, npm, cloud, Vault, Kubernetes, database, and private-key material, as well as read GitHub Actions runner memory, install a token-revocation watcher, and carry npm publishing machinery. The attack was designed to spread quickly across multiple organizations, with the malicious release spreading beyond the Keyv and Cacheable namespaces into hundreds of packages.

    The worm's authors cleverly used OpenID Connect (OIDC) and Supply-chain Levels for Software Artifacts (SLSA) provenance to make the attack appear legitimate. However, a close examination of the commit records verified that the source entering it was not safe. The authors also employed a technique called "campaign-wide list" to create a malicious campaign that could not be independently mapped package by package.

    The attack has raised concerns about the security of the npm ecosystem, with many organizations being left vulnerable to this devastating supply chain attack. According to SafeDep, a credential-stealing npm worm spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. The malicious release used a preinstall script to run a credential-stealing bundle inside developer and continuous integration (CI) environments.

    SafeDep verified 353 poisoned versions across 79 package names in the npm registry, while Aikido reported at least 868 packages across 1,381 versions. However, neither of these totals could be independently reproducible from a complete public list at the reporting cutoff. The worm's payload analysis revealed that it could harvest repository, package registry, cloud, and private-key material, as well as read GitHub Actions runner memory, install a token-revocation watcher, and carry npm publishing machinery.

    The attack has significant implications for the security of many organizations, particularly those that rely heavily on third-party libraries and dependencies. It highlights the need for better vulnerability management and supply chain security practices to prevent similar attacks in the future.

    In an effort to mitigate the impact of this devastating supply chain attack, SafeDep advises responders to remove the malware's credential-revocation watcher before rotating exposed tokens and keys. The researchers also recommend that teams compare lockfiles and resolved versions against the affected-package list, disable unnecessary install scripts, and treat environments that executed an affected release as compromised.

    Furthermore, the researchers counted 546 public GitHub repositories created on August 4 with the description "Shai-Hulud: Here We Go Again" and a results/directory. These repositories are potential exfiltration or staging artifacts, not confirmed victims. In conclusion, this devastating supply chain attack highlights the need for better vulnerability management and supply chain security practices to prevent similar attacks in the future.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/A-Devastating-Supply-Chain-Attack-A-Comprehensive-Analysis-of-the-Keyv-Linked-npm-Worm-ehn.shtml

  • https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html


  • Published: Tue Aug 4 10:28:34 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us