Keyv Ecosystem Hit by npm Supply Chain Attack with Over 2,000 Malicious Versions
Over 2,000 malicious npm packages targeting Keyv ecosystem detected, risking credential theft and CI/CD leakage for 127M weekly downloads.
Woofun AI reports that MistEye identified a large-scale npm supply chain attack compromising the Keyv and Cacheable ecosystems. Attackers distributed more than 2,000 malicious package versions, including keyv@6.0, exploiting the library's 127 million weekly downloads to create significant downstream exposure.
The campaign mirrors the Shai-Hulud npm worm in automation and scalability. Potential risks include credential theft, environment variable leakage, and lateral propagation via compromised development environments. Security teams are advised to remove affected versions, verify dependencies, rotate credentials, and rebuild impacted systems.
Comments
No comments yet.