SlowMist Flags Massive npm Supply-Chain Attack Aimed at Keyv Ecosystem
AI Market Summary
SlowMist reports a large-scale npm supply-chain compromise targeting the widely used Keyv/Cacheable ecosystem, with 2,000+ malicious package versions and massive downstream exposure via CI/CD and dependency trees. This heightens operational and security risk for crypto and fintech infrastructure that relies on JavaScript tooling, raising the probability of credential leakage, wallet/key compromise, and service disruptions. Near-term, it can dampen risk appetite for the broader crypto complex.
Impact level
● Medium
Affected assets
BTC/USDT+0.98%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Blockchain security firm SlowMist (@SlowMist_Team) said its MistEye threat-intelligence platform has identified a large-scale npm supply-chain attack targeting the Keyv/Cacheable ecosystem. The attackers reportedly published more than 2,000 malicious package versions, including key components such as keyv@6.0.0.
Keyv is a widely used key-value storage abstraction library that supports backends including Redis, SQLite, PostgreSQL and MongoDB. SlowMist estimates Keyv sees roughly 127 million downloads per week, raising the potential for significant downstream supply-chain exposure.
SlowMist noted the operation closely mirrors the previously observed ShaiHulud npm worm campaign, with a high degree of automation and scalability. Potential impacts include credential theft, environment variable exposure, CI/CD secret leakage, remote payload delivery and lateral movement.
SlowMist urged security teams to immediately locate and remove affected versions, upgrade to verified safe releases, review dependency lock files and build logs, monitor for suspicious outbound connections, rotate any potentially exposed credentials, and rebuild impacted environments from trusted sources if compromise is suspected.