keyv and cacheable npm Package Hijacked in Supply Chain Attack

Published: Aug 4, 2026 — Wiz Blog (updated 1345 UTC)

Multiple npm packages in the keyv/cacheable ecosystem were compromised following GitHub maintainer account compromise. All versions shared a consistent payload. Starting ~09:00 UTC, attacker introduced IDE persistence payloads to the keyv repository, then published malicious keyv. Worm propagated to over 400 distinct npm packages (Wiz count at update time; see Wiz GitHub for full list).

Attribution / family

  • Payload is a descendant of the “Mini” Shai-Hulud malware family
  • Similarities with TeamPCP and antv supply chain campaigns
  • User-agent IOC: Bun/1.3.13
  • Exfil domain IOC: npm-cache[.]com (104.21.35[.]216, Cloudflare)

Spread

Compromised packages include org-scoped packages beyond keyv/cacheable (e.g. @ornikar/, @qlik/, Picsart-related, Deliveroo-related per broader industry reporting).