BlockBeats report, August 5: SlowMist announced the detection of a large-scale npm supply chain attack targeting the Keyv/Cacheable ecosystem. The attackers have published over 2,000 malicious package versions within the ecosystem, including keyv@6.0.0.
Keyv is a widely used key-value storage abstraction layer that supports backends such as Redis, SQLite, PostgreSQL, and MongoDB, with approximately 127 million weekly downloads, potentially posing a broad downstream supply chain risk.
This attack technique bears strong similarity to previous Shai-Hulud npm worm activity, indicating high levels of automation and spreading capability. Potential behaviors include stealing credentials, exfiltrating environment variables, leaking CI/CD keys, remotely delivering payloads, and lateral movement through compromised development environments.
Recommend that the security team immediately identify and remove affected versions, upgrade to verified secure versions, inspect dependency lock files and build logs, monitor for anomalous outbound connections, and rotate credentials that may have been exposed; if environment compromise is suspected, rebuild from trusted sources.
