[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active--mshcpozv":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":18,"article_ids":19,"ioc_summary":21,"source_urls":22,"status":24,"expires_at":25,"created_at":26,"updated_at":27,"articles":28},"b09b8221-0491-4074-b9a3-f29db25bfab2","Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack","popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active--mshcpozv","At least 10 npm packages in the keyv and cacheable namespaces were compromised on August 4, 2026 with malicious preinstall hooks that download Bun runtime, steal cloud\u002FCI credentials, and propagate via stolen npm tokens. Tens of millions of weekly downloads are affected through transitive dependencies. Any organization using these packages or their dependents is at immediate risk of credential theft and supply chain propagation.","critical","advisory",[],[13,14,15,16,17],"keyv","cacheable","cacheable-request","flat-cache","file-entry-cache","Immediately audit npm dependencies for keyv and cacheable packages; if present, revoke all npm tokens, cloud credentials, and CI\u002FCD secrets that could have been accessed during installation; scan build logs and package-lock files for suspicious preinstall activity dating back to August 4, 2026.",[20],"0e5d4a09-fdb2-45b2-bbb1-33d2404daf6d",null,[23],"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fpopular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain?utm_medium=feed","archived","2026-08-08T10:06:31.417+00:00","2026-08-06T10:06:34.778274+00:00","2026-08-08T11:05:44.306535+00:00",[29],{"id":20,"title":6,"url":23}]