PANews
PANews|Aug 05, 2026 03:42
[SlowMist: Keyv Ecosystem Hit by Large-Scale npm Supply Chain Attack, Over 2,000 Malicious Package Versions Released] According to monitoring by SlowMist, MistEye has detected a large-scale npm supply chain attack affecting the Keyv/Cacheable ecosystem. The attackers released over 2,000 malicious package versions, including keyv@6.0.0. Keyv is a widely used key-value storage abstraction library that supports backends such as Redis, SQLite, PostgreSQL, and MongoDB, with approximately 127 million weekly downloads, leading to significant downstream supply chain exposure. The attack methods are highly similar to the previous Shai-Hulud npm worm activity, pointing to a highly automated and scalable supply chain attack. Potential attack behaviors include credential theft, environment variable leaks, CI/CD key leaks, remote payload delivery, and lateral movement through compromised development environments.
Share To

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads