Popular npm Packages in keyv/cacheable Namespaces Compromised

Published: Aug 4, 2026 — Socket Threat Research Team

Active supply chain compromise affecting keyv and cacheable npm packages. At least ten packages in those namespaces (spreading to other maintainers) published with malicious preinstall hook (setup.mjs) that downloads standalone Bun runtime, executes obfuscated second stage, harvests cloud/CI credentials, and republishes trojanized versions via stolen npm tokens.

Tradecraft

  • Maintainer account (Jaredwray) compromised; used to publish across two package families
  • Credential theft: cloud IMDS, AWS/GCP/Azure keys, Vault, K8s SA tokens, GitHub Actions OIDC, npm tokens
  • TruffleHog-style regex sweep; staging stolen data into threat-actor GitHub repos via GitHub API
  • Matches Shai-Hulud worm techniques including OIDC trusted publishing abuse
  • cacheable family published in burst 10:09:44–10:14:41 UTC