Keyv/Cacheable Ecosystem Targeted in Major npm Supply-Chain Attack; 2,000+ Malicious Package Versions Published
AI Market Summary
SlowMist reports a large-scale npm supply-chain attack hitting the widely used Keyv/Cacheable ecosystem, with 2,000+ malicious package versions and major downstream exposure. The risk of credential theft, CI/CD secret leakage, and remote payload delivery raises operational and counterparty risk across crypto and fintech teams reliant on JavaScript tooling. Near term, this can dampen risk appetite and increase security-driven disruption as projects rotate credentials and rebuild environments.
Impact level
● Medium
Affected assets
BTC/USDT+0.75%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
ChainCatcher reports that SlowMist monitoring shows MistEye has identified a large-scale npm supply-chain attack aimed at the Keyv/Cacheable ecosystem. The attacker is said to have published more than 2,000 malicious package versions, including keyv@6.0.
Keyv is a widely used key-value storage abstraction library with support for Redis, SQLite, PostgreSQL, and MongoDB. With roughly 127 million weekly downloads, the incident creates substantial downstream supply-chain risk.
SlowMist noted the tactics closely resemble prior ShaiHulud npm worm activity, suggesting a highly automated, scalable campaign. Suspected capabilities include credential theft, environment variable leakage, CI/CD secret exposure, remote payload delivery, and lateral movement via compromised development environments.
Security teams are advised to promptly identify and remove impacted versions, upgrade to verified safe releases, review dependency lock files and build logs, monitor for suspicious outbound connections, rotate any potentially exposed credentials, and rebuild affected environments if compromise is confirmed.