According to monitoring by blockchain security firm SlowMist (@SlowMist_Team), its threat intelligence system MistEye detected a large-scale npm supply chain attack targeting the Keyv/Cacheable ecosystem. The attackers published over 2,000 malicious package versions, including core components such as keyv@6.0.0. Keyv, a widely used key-value storage abstraction library supporting backends like Redis, SQLite, PostgreSQL, and MongoDB, receives approximately 127 million weekly downloads, exposing its downstream supply chain to significant risk. This attack technique closely resembles the previously observed Shai-Hulud npm worm campaign, exhibiting high levels of automation and scalability. Potential risks include credential theft, environment variable exposure, CI/CD secret leakage, remote payload delivery, and lateral movement. SlowMist recommends that security teams immediately identify and remove affected package versions, upgrade to verified secure versions, review dependency lock files and build logs, monitor for suspicious outbound connections, rotate exposed credentials, and rebuild affected environments from trusted sources if compromise is suspected.
SlowMist Detects Large-Scale npm Supply Chain Attack Targeting the Keyv Ecosystem
TechFlowShare
On-chain news reveals a large-scale npm supply chain attack targeting the Keyv/Cacheable ecosystem, reported by blockchain security firm SlowMist. Over 2,000 malicious package versions were published, including keyv@6.0.0, a widely used library with 127 million weekly downloads. The attack mirrors the Shai-Hulud worm, enabling credential theft, environment exposure, and lateral movement. SlowMist urged teams to remove affected versions, upgrade to secure ones, and rebuild from trusted sources if compromised. The incident highlights the need for vigilance as the ecosystem continues to grow.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.
