CRITICALAdvisoryAug 06, 2026
Action required
Immediately audit npm dependencies for keyv and cacheable packages; if present, revoke all npm tokens, cloud credentials, and CI/CD secrets that could have been accessed during installation; scan build logs and package-lock files for suspicious preinstall activity dating back to August 4, 2026.
Affected products
keyvcacheablecacheable-requestflat-cachefile-entry-cache
Linked articles