SlowMist|8月 05, 2026 03:39
🚨 SlowMist TI Alert 🚨
MistEye has detected a large-scale npm supply chain compromise impacting the Keyv/Cacheable ecosystem. Attackers published over 2,000 malicious package versions across the affected ecosystem, including keyv@6.0.0. Keyv, a widely used key-value storage abstraction with adapters for Redis, SQLite, PostgreSQL, MongoDB, and other backends, has roughly 127 million weekly downloads, leading to significant downstream supply chain exposure.
The attackers' tradecraft closely mirrors techniques previously observed in the Shai-Hulud npm worm campaign, pointing to a highly automated and scalable supply chain attack. Potential attacker actions include credential theft, environment variable exfiltration, CI/CD secret compromise, remote payload delivery, and lateral propagation through compromised development environments.
Security teams should immediately identify and remove affected package versions, upgrade to verified safe releases, review dependency lockfiles and build logs, monitor for suspicious outbound connections, rotate exposed credentials, and rebuild impacted environments from trusted sources if compromise is suspected.
You can also visit https://www.misteye.io/ to check for free whether the npm packages, pip packages, domains, or IPs you use are safe.
As always, stay vigilant!
https://enterprise.misteye.io/threat-intelligence/SM-2026-600977(SlowMist)
Share To
HotFlash
APP
X
Telegram
CopyLink