keyv and cacheable npm Package Hijacked in Supply Chain Attack
Published: Aug 4, 2026 — Wiz Blog (updated 1345 UTC)
Multiple npm packages in the keyv/cacheable ecosystem were compromised following GitHub maintainer account compromise. All versions shared a consistent payload. Starting ~09:00 UTC, attacker introduced IDE persistence payloads to the keyv repository, then published malicious keyv. Worm propagated to over 400 distinct npm packages (Wiz count at update time; see Wiz GitHub for full list).
Attribution / family
- Payload is a descendant of the “Mini” Shai-Hulud malware family
- Similarities with TeamPCP and antv supply chain campaigns
- User-agent IOC:
Bun/1.3.13 - Exfil domain IOC:
npm-cache[.]com(104.21.35[.]216, Cloudflare)
Spread
Compromised packages include org-scoped packages beyond keyv/cacheable (e.g. @ornikar/, @qlik/, Picsart-related, Deliveroo-related per broader industry reporting).