NPM · AUGUST 2026 · CONFIRMED

keyv and cacheable npm Packages Compromised in Supply Chain Attack

Severity: HIGH

The popular npm packages keyv and cacheable were compromised in an active supply chain attack. The packages may contain malicious code that harvests credentials and spreads to other packages.

What happened

On August 4, 2026, an attacker took over the maintainer account behind the keyv and cacheable npm namespaces and published trojanized releases. The malicious versions include a preinstall hook that downloads and executes obfuscated code to harvest credentials and inject the hook into other packages. The attack has impacted hundreds of packages across multiple organizations.

The compromised versions of keyv and cacheable include keyv@6.0.0 and cacheable@2.5.1. The malicious code can harvest AWS instance metadata, cloud keys, Vault tokens, Kubernetes service-account tokens, GitHub Actions secrets, npm tokens, and private keys. It then uses stolen npm tokens to inject the hook into other packages, causing the attack to spread rapidly.

To assess your exposure, check if you are using keyv@6.0.0 or cacheable@2.5.1 or any dependent packages. Look for signs of compromise such as unexpected credential access or unusual network activity. Consider using alternative packages and rotating any exposed credentials. For more details, consult the primary sources.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If keyv is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats