#keyv
Kourosh Keyvani, an Iranian-Swedish dual national, was executed on charges of “spying for Israel" on 18 March 2026.

www.en-hrana.org/kourosh-keyv...
March 24, 2026 at 1:10 PM
щойно написав keyv маючи на увазі київ. посипався
August 13, 2025 at 3:36 PM
🚨 An npm worm is spreading live, while half of the security industry is at #BlackHat in Vegas. talk about timing!

@socket.dev is now tracking 2,234 malicious package artifacts across 444 unique packages in the keyv/cacheable compromise.

Average detection time: 5 min 18 sec after publication
Popular npm Packages in the keyv and Cacheable Namespaces Co...
Popular npm packages keyv and cacheable compromised.
socket.dev
August 4, 2026 at 2:46 PM
🚨 Active npm supply chain attack: keyv​@​6.0.0 and 13 other packages have been compromised. keyv alone gets 154M weekly downloads.

The worm steals cloud and CI credentials, then uses stolen npm tokens to publish trojanized versions of more packages.
August 4, 2026 at 12:20 PM
⚠️ JS supply chain attack ongoing:
The GitHub account of the maintainer behind keyv was compromised recently - Shai Halud style.

www.aikido.dev/blog/keyv-an...
Keyv and friends compromised in npm supply chain attack
Mini Shai-Hulud malware was injected into keyv and eight related npm packages on August 4, 2026 after an attacker compromised the maintainer's GitHub account
www.aikido.dev
August 4, 2026 at 2:10 PM
In Keyv, the boys and girls can be slutty!
September 10, 2026 at 10:42 PM
Happy birthday Keyv’ !! 🥳
August 8, 2025 at 9:52 AM
Active exploits found by none other than the great and all powerful @feross.bsky.social & co

socket.dev/blog/popular...
Popular npm Packages in the keyv and Cacheable Namespaces Co...
Popular npm packages keyv and cacheable compromised.
socket.dev
August 4, 2026 at 12:32 PM
🚨 Another npm worm is live right now. It landed the same week npm turned on publish-time malware scanning, and after npm killed long-lived tokens in favor of OIDC trusted publishing.

It propagates through trusted publishing. keyv@6.0.0 even shipped with passing provenance.
August 4, 2026 at 2:35 PM
We reviewed actions/setup-java released versions v1–v5 and main, against today’s Keyv/Cacheable npm supply-chain attack.

No compromised versions or known IOCs were found in the lockfiles or shipped bundles.

This is a point-in-time assessment:

github.com/actions/setu...
Security review: Keyv/Cacheable npm supply-chain incident · Issue #1193 · actions/setup-java
Summary As of 2026-08-04, the current actions/setup-java dependency tree and distributed JavaScript bundles are not affected by the Keyv/Cacheable npm supply-chain attack reported by Wiz Research. ...
github.com
August 4, 2026 at 3:18 PM
New npm Supply Chain Attack Began with the Keyv Library Compromised Hundreds of Popular Packages
New npm Supply Chain Attack Began with the Keyv Library Compromised Hundreds of Popular Packages
A new npm supply chain attack has turned trusted software packages into a route for credential theft. The campaign began after attackers compromised the maintainer account behind the widely used Keyv library, then used that access to push malicious releases across a growing number of projects. The incident matters because npm packages are routinely installed automatically during development and build work. A poisoned dependency can therefore reach laptops, servers, and automated pipelines without an employee ever visiting a suspicious website or opening a malicious attachment. Microsoft and Socket identified the activity as an active Mini Shai-Hulud campaign, a self-spreading malware operation built to steal access tokens and reuse them.  Microsoft  and  Socket  said in reports shared with Cyber Security News (CSN) that the attackers appeared to be using multiple stolen publishing tokens. The scale expanded quickly. Socket reported 2,234 affected package artifacts across 444 unique packages while the activity was still spreading, showing how a single compromised maintainer can create a broad downstream risk for teams worldwide that rely on open-source code. New npm Supply Chain Attack Began The attack started with a compromise of the trusted account associated with Keyv, a commonly used key-value storage library. Once the attackers gained publishing access, they could release altered packages that looked like ordinary updates and were available through the normal npm installation process. That initial foothold gave the campaign an unusually large audience. Keyv has a substantial weekly download base, so its compromise placed a familiar dependency at the center of a wider incident and renewed concern over  Keyv package compromise details , where trusted update channels become the delivery path. The malicious releases use an install-time instruction to begin the attack before a developer can use the package. Update: Watching this npm worm propagate in real time, we’re now tracking 2,234 affected package artifacts across 444 unique packages, and it’s still spreading. Average detection time: 5 min and 18 seconds after publication. Our campaign page includes all packages/versions. https://t.co/BQcxGtIQVV — Socket (@SocketSecurity) August 4, 2026 Instead of stopping at one machine, the malware searches for credentials that can let it publish altered releases from other maintainers, producing a chain reaction across the registry. This behavior makes the incident different from a simple one-off package poisoning. The threat is designed to move through software publishing relationships, meaning each stolen token can open another path to developers, build systems, and organizations that depend on those packages. The campaign also fits a troubling pattern seen in recent  npm credential theft campaigns . In those attacks, criminal operators focus on the accounts and automation that publish code, knowing that one legitimate account can be more useful than a large volume of fake packages. Stolen Tokens Fuel Wider Risk After it runs, the malware hunts for credentials connected to npm, code-hosting accounts, cloud services, and continuous integration systems. These secrets can provide access far beyond the affected project, particularly where a build system has permission to publish packages or deploy software. The stolen information is sent out of the victim environment, after which publishing access is used to alter package archives, raise their version numbers, and release them again. That automated loop helps explain why analysts saw the number of affected artifacts climb so fast. Teams should treat any installation of a listed malicious release as a potential credential exposure, not merely a bad dependency update. They should remove affected versions, rebuild dependency lockfiles from trusted information, and review recent package changes before allowing automated deployments to continue. Credential rotation is equally important. npm tokens, code-hosting access tokens, cloud keys, and continuous integration secrets available on impacted hosts should be revoked and replaced, while maintainers should check repositories and publishing histories for unexpected releases or workflow edits. Organizations can reduce future exposure by requiring multi-factor authentication for publishing accounts, using short-lived and narrowly scoped automation credentials, and separating build permissions from release permissions. Monitoring unusual package versions and unexpected install behavior can also help catch a recurrence earlier. For added context, readers can review coverage of the Mini Shai-Hulud attack wave and  software supply chain defenses . The immediate lesson is straightforward: trust in a package name is not enough in everyday production work when a maintainer account or its publishing token has been compromised. Indicators of Compromise (IoCs):- Type Indicator Description Compromised npm package keyv@6.0.0 Confirmed malicious package release Compromised npm package file-entry-cache@11.1.6 Confirmed malicious package release Compromised npm package cache-manager@7.2.10 Confirmed malicious package release Compromised npm package cacheable-request@13.0.20 Confirmed malicious package release Compromised npm package qlik/api@2.14.2 Confirmed malicious package release Compromised npm package cacheable/memory Affected package identified in the campaign Compromised npm package cacheable/utils Affected package identified in the campaign Compromised npm package cacheable/net Affected package identified in the campaign Compromised package scope servicetitan/* More than 17 affected packages, including  eslint-config ,  anvil-themes ,  table ,  form , and  log-service Malicious file setup.mjs Obfuscated dropper launched through the malicious preinstall hook Malicious file Math_Symbol.js Credential-stealing payload Malicious file Math_Init.js Credential-stealing payload Detection name Trojan:npm/MalBun.A Microsoft Defender for Endpoint detection name Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Stop new phishing & malware before they compromise your business.  Integrate live intel from 15K SOCs around the world The post New npm Supply Chain Attack Began with the Keyv Library Compromised Hundreds of Popular Packages appeared first on Cyber Security News .
cybersecuritynews.com
August 6, 2026 at 5:39 AM
Ce week-end, le site du « Monde diplomatique » dévoile l'épopée du Proche-Orient. Nos archives sont en libre accès de vendredi soir à dimanche.

La rédaction vous recommande : « Les Iraniennes allument un brasier social », par Mitra Keyvan.

www.monde-diplomatique.fr/2022/11/KEYV...
June 29, 2025 at 10:01 AM
An added preinstall hook downloads Bun to execute an obfuscated payload that steals credentials. The attack also plants autostart hooks in .claude and .vscode that can run when a developer or AI coding agent opens the repo, with no npm install required.

socket.dev/blog/popular...
Popular npm Packages in the keyv and Cacheable Namespaces Co...
Popular npm packages keyv and cacheable compromised.
socket.dev
August 4, 2026 at 12:20 PM
Well the historical Gallicia has I think been ruled by Keyv at points, though I don't think very recently.
June 18, 2025 at 6:51 PM
Last week keyv and many other packages got compromised, billions of installs compromised.

One big issue for many packages is that the GitHub account or SSH key is enough to publish packages...
August 8, 2026 at 3:56 PM
Researchers: ChainDrop, a Shai-Hulud-based worm, compromised 1,300+ npm packages, including Keyv and Cacheable, with a combined 2B monthly downloads (Bill Toulas/BleepingComputer)

Main Link | Techmeme Permalink
August 4, 2026 at 3:45 PM
November 29, 2024 at 5:13 PM
Planning out Keyv version 6 and thinking about moving all packages to the same version lock as Keyv like vitest does. Thoughts?

#javascript #typescript #nodejs

github.com/jaredwray/keyv
GitHub - jaredwray/keyv: Simple key-value storage with support for multiple backends
Simple key-value storage with support for multiple backends - jaredwray/keyv
github.com
November 13, 2025 at 12:23 AM
Waiting for NPM to allow me to release my staged package... This is becoming truely annoying, especially knowing it didn't catch the keyv leak and having reviewed the release myself on drydock.
August 10, 2026 at 6:20 AM
Popular npm packages keyv and cacheable were hijacked, and malicious versions containing a malware were released to steal users’ access tokens.

Protect your packages from the same fate with my guide, based on maintaining PostCSS and 100+ other projects:

evilmartians.com/chronicles/t...
@sitnik_en@mastodon.social (@sitnikcode) on X
Popular npm packages Keyv and Cacheable were hijacked, and malicious versions containing a malware were released to steal users’ access tokens. Protect your packages from the same fate with my guide,...
x.com
August 4, 2026 at 3:00 PM
The popular npm package, keyv, has been compromised with malware.

With npm staged publish or drydock environment gates this would not have happened.... The release is ungated OIDC publishing to npm so just a compromised GitHub account is enough...

github.com/jaredwray/ke...
github.com
August 4, 2026 at 11:30 AM