keyv and cacheable npm Package Hijacked in Supply Chain Attack

Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages.

Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple npm packages in the Keyv/Cacheable ecosystem. This blog presents our initial findings based on the analysis completed so far. As our investigation continues, we will update this post with additional technical details, indicators of compromise, attribution insights, and any newly identified affected packages or infrastructure.

August 4, 2026, 1345 UTC update: Many additional packages have been compromised, see the full list over on our GitHub. Wiz identified the user-agent Bun/1.3.13 performing malicious calls related to this activity, and added it to the IOCs section.

What happened?

Multiple npm packages in the keyv/cacheable ecosystem were compromised following the compromise of a GitHub maintainer account, resulting in the publication of malicious package versions. All versions shared a consistent payload. Starting at 9:00 UTC, the attacker first used a compromised identity to introduce IDE persistence payloads to the keyv repository, and then shortly after published a new version of keyv containing their payload.

Wiz analysis indicates the payload is a descendant of the "Mini" Shai-Hulud malware family, sharing similarities with the TeamPCP and antv supply chain campaigns.

The malware targets a broad range of sensitive data, including cloud credentials, infrastructure secrets, developer credentials, AI-related configuration files, and cryptocurrency wallets. It also attempts to harvest secrets from CI/CD environments, identify build runners, and enumerate cloud environments to facilitate credential theft and further compromise.

Data is exfiltrated via GitHub repositories created under compromised identities, using the description Shai-Hulud: Here We Go Again, matching the Shai-Hulud code that was previously open-sourced. A new intimidation string is used in the initial commits, IfYouBlockThisAPIKeyItWillCrashTheLiveProductionServersOfAllThirdPartyClients.

What steps should security teams take?

  1. Identify and remove the affected package versions from development, build, and CI/CD environments.

  2. Treat affected systems as potentially compromised and rebuild them if the malicious packages were installed.

  3. Rotate exposed credentials, including cloud credentials, GitHub tokens, SSH keys, Kubernetes configurations, Terraform credentials, and other developer secrets.

  4. Review cloud and source code environments for unauthorized access or suspicious activity following package installation.

  5. Monitor for the published IOCs, including the identified domains, file artifacts, and other indicators associated with the campaign.

  6. Strengthen software supply chain defenses by enabling dependency allowlisting, package integrity verification, and provenance controls where available.

Affected Packages

Track the full list of impacted packages over on our GitHub.

PackageMalicious Version
@cacheable/utils2.5.1
@hubsync/web-sdk-react6.3.7
@nebula.js/nucleus0.5.1
@ornikar/babel-preset-base6.0.3
@ornikar/babel-preset-kitt-universal8.0.3
@ornikar/babel-preset-react6.1.4
@ornikar/browserslist-config8.0.3
@ornikar/commitlint-config8.3.2
@ornikar/eslint-config-babel24.0.1
@ornikar/eslint-config-react24.0.1
@ornikar/eslint-config-typescript24.0.1
@ornikar/eslint-config-typescript-react24.0.1
@ornikar/eslint-plugin-neverthrow1.3.1
@ornikar/eslint-plugin-ornikar24.0.1
@ornikar/graphql-config1.1.1
@ornikar/intl-config10.0.2
@ornikar/kitt21.0.1
@ornikar/monorepo-config14.3.2
@ornikar/postcss-config9.1.2
@ornikar/prettier-config9.0.3
@ornikar/prismic-components0.0.2
@ornikar/react-modern-calendar-datepicker3.2.1
@ornikar/react-native-svg-transformer1.0.6
@ornikar/renovate-config9.0.2
@ornikar/repo-config-react13.0.8
@ornikar/repo-config-react-legacy-css15.1.2
@ornikar/rollup-plugin-postcss2.0.5
@ornikar/stylelint-config14.0.3
@ornikar/typed-css-modules-loader0.8.2
@qlik/embed-react2.5.3
@qlik/embed-runtime1.6.4
@qlik/embed-web-components1.7.3
@qlik/runtime-module-loader1.5.1
@thiennq/docs-viewer1.6.2
babel-plugin-linaria-css-to-undefined0.3.1
cache-manager7.2.10
cacheable-request13.0.20
http-metrics-middleware2.2.2
keyv6.0.0
picasso-plugin-hammer2.11.6
picasso-plugin-q2.11.6
pob-test-package-in-monorepo5.2.1

Indicators of Compromise (IOCs)

Domains

  • npm-cache[.]com - Exfil domain (104.21.35[.]216, Cloudflare)

  • eth-mainnet.nodereal[.]io - ETH RPC (35.175.164[.]77, Amazon)

  • go.getblock[.]io - ETH RPC (185.44.207.215)

  • eth.llamarpc[.]com - ETH RPC (172.67.167.200, Cloudflare)

User-agents

  • Bun/1.3.13

File Artifacts

  • /tmp/bun-dl-*/

  • node_modules/keyv/Math_Symbol.js

FileHash
Math_Symbol.js

35a672cf34b996b91f3e1c28cbf3a05a37e036e4

math_init.js35a672cf34b996b91f3e1c28cbf3a05a37e036e4
setup.mjs (in .claude)686aa40d0fc22c8d569494543a0f891f359f2f99
setup.mjs (in .vscode)f525d52ceb966516686b482d3dc0137028cc6a63

Strings / Attribution Indicators

  • IfYouBlockThisAPIKeyItWillCrashTheLiveProductionServersOfAllThirdPartyClients

Continue reading

S3 Clones in the Neoclouds

S3 compatible services carry many of the same concerns as the original S3 service. This article highlights which assumptions break and what risks remain.

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management