ChainCatcher report: According to SlowMist monitoring, MistEye has detected a large-scale npm supply chain attack targeting the Keyv/Cacheable ecosystem. The attacker has released over 2,000 malicious package versions, including keyv@6.0. Keyv is a widely used key-value storage abstraction library supporting backends such as Redis, SQLite, PostgreSQL, and MongoDB, with approximately 127 million weekly downloads, resulting in significant downstream supply chain exposure. The attack technique closely resembles the previous Shai-Hulud npm worm activity, indicating a highly automated and scalable supply chain attack. Potential malicious activities include credential theft, environment variable leakage, CI/CD secret exposure, remote payload delivery, and lateral movement through compromised development environments. Security teams should immediately identify and remove affected package versions, upgrade to verified secure versions, review dependency lock files and build logs, monitor for suspicious outbound connections, rotate compromised credentials, and rebuild environments upon confirmation of compromise.
Keyv Ecosystem Hit by Large-Scale npm Supply Chain Attack with Over 2,000 Malicious Packages
ChaincatcherShare
A new on-chain news alert reveals a large-scale npm supply chain attack targeting the Keyv/Cacheable ecosystem, with over 2,000 malicious packages published. Keyv, a key-value storage library with 127 million weekly downloads, is now at risk. The attack mirrors the Shai-Hulud worm, enabling credential theft, CI/CD key exposure, and lateral movement. Security teams are urged to audit dependencies, remove affected versions, and rebuild compromised environments. The incident highlights the need for stronger ecosystem growth and supply chain security.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.
