isc.sans.edu 8/5/2026, 7:02:05 PM · external

Compromised keyv and cacheable npm packages leak secrets silently

Compromised keyv and cacheable npm packages leak secrets silently
CyberSIXT Evidence Panel
Primary Source github.com

THE article discusses a supply-chain attack involving the `keyv` and `cacheable` npm packages, which were compromised on August 4, 2026. An attacker took over the maintainer account and published infected versions of these libraries that included malicious scripts designed to harvest sensitive information such as cloud keys and GitHub secrets. Notably, this attack does not require running `npm install` to execute, making it particularly dangerous.

Remediation advice emphasizes that simply revoking tokens is insufficient; it can trigger further malicious actions. Instead, the recommended response involves immediate isolation of the compromised host, preserving evidence, and methodically eradicating the threat before rotating any credentials. The article also highlights that many checks often miss compromised packages because the malicious changes can exist without altering the package's evident contents.

A tool developed for triaging this type of incident is introduced, which helps automate the identification of compromised packages and suggests a response strategy.

View Primary Source Via isc.sans.edu

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline