keyv and cacheable npm Package Hijacked in Supply Chain Attack | Wiz Blog*:not([data-layout="full-bleed"])]:col-start-2">
Wiz
PricingGet a demo
Get a demo
*:not([data-layout="full-bleed"])]:col-start-2 lg:hidden">
*:not([data-layout="full-bleed"])]:col-start-2">
:first-child]:text-primary-blue group-data-[theme=brand]:prose-blockquote:border-white group-data-[theme=brand]:prose-blockquote:text-white group-data-[theme=brand]:[&_cite]:text-secondary-blue-medium group-data-[theme=brand]:[&_cite>:first-child]:text-secondary-blue-light prose-code:rounded-md prose-code:bg-secondary-blue-medium/10 prose-code:p-1 prose-code:font-mono prose-code:font-normal prose-code:break-all prose-code:text-primary-blue prose-code:before:hidden prose-code:after:hidden group-data-[theme=brand]:prose-code:bg-secondary-blue-dark group-data-[theme=brand]:prose-code:text-secondary-blue-medium dark-research:prose-figcaption:text-gray-light dark-research:marker:text-pink-research dark-research:prose-headings:text-white dark-research:prose-a:text-pink-research dark-research:prose-blockquote:border-pink-research dark-research:prose-blockquote:text-white dark-research:[&_cite]:text-gray-light dark-research:[&_cite>:first-child]:text-pink-research dark-research:prose-code:bg-pink-research/10 dark-research:prose-code:text-pink-research">Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple npm packages in the Keyv/Cacheable ecosystem. This blog presents our initial findings based on the analysis completed so far. As our investigation continues, we will update this post with additional technical details, indicators of compromise, attribution insights, and any newly identified affected packages or infrastructure.
What happened?<br>Multiple npm packages in the keyv/cacheable ecosystem were compromised following the compromise of a GitHub maintainer account, resulting in the publication of malicious package versions. All versions shared a consistent payload. Starting at 9:00 UTC, the attacker first used a compromised identity to introduce IDE persistence payloads to the keyv repository, and then shortly after published a new version of keyv containing their payload.<br>Wiz analysis indicates the payload is a descendant of the "Mini" Shai-Hulud malware family , sharing similarities with the TeamPCP and antv supply chain campaigns.<br>The malware targets a broad range of sensitive data, including cloud credentials, infrastructure secrets, developer credentials, AI-related configuration files, and cryptocurrency wallets. It also attempts to harvest secrets from CI/CD environments, identify build runners, and enumerate cloud environments to facilitate credential theft and further compromise.<br>Data is exfiltrated via GitHub repositories created under compromised identities, using the description Shai-Hulud: Here We Go Again, matching the Shai-Hulud code that was previously open-sourced. A new intimidation string is used in the initial commits, IfYouBlockThisAPIKeyItWillCrashTheLiveProductionServersOfAllThirdPartyClients.
What steps should security teams take?<br>Identify and remove the affected package versions from development, build, and CI/CD environments.
Treat affected systems as potentially compromised and rebuild them if the malicious packages were installed.
Rotate exposed credentials, including cloud credentials, GitHub tokens, SSH keys, Kubernetes configurations, Terraform credentials, and other developer secrets.
Review cloud and source code environments for unauthorized access or suspicious activity following package installation.
Monitor for the published IOCs, including the identified domains, file artifacts, and other indicators associated with the campaign.
Strengthen software supply chain defenses by enabling dependency allowlisting, package integrity verification, and provenance controls where available.
Affected Packages<br>Track the full list of impacted packages over on our GitHub.<br>PackageMalicious...