MistEye detected a large-scale npm supply chain attack affecting the Keyv and Cacheable ecosystem, with attackers publishing more than 2,000 malicious package versions, including keyv@6.0. Keyv is a widely used key-value storage abstraction library with about 127 million weekly downloads, creating significant downstream supply chain exposure, according to ChainCatcher.
The attack method was said to closely resemble the earlier Shai-Hulud npm worm activity, suggesting a highly automated and scalable campaign. Potential malicious actions include credential theft, environment variable leakage, CI/CD secret exposure, remote payload delivery, and lateral movement through compromised development environments. Security teams were urged to remove affected package versions, upgrade to verified safe versions, review dependency lockfiles and build logs, monitor suspicious outbound connections, rotate exposed credentials, and rebuild environments after confirming exposure.
