← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 4, 2026 · 10:36via Socket Security Blog

Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack

Brief

Socket’s Threat Research Team is tracking an active supply chain compromise affecting the widely used keyv and cacheable npm packages. On August 4, 2026, at least ten packages beginning with the keyv and cacheable namespaces and spreading to packages owned by other maintainers, were published with a malicious preinstall hook ( setup.

mjs ) that downloads a standalone Bun runtime, executes an obfuscated second stage, harvests cloud and CI credentials, and republishes trojanized versions of other packages the stolen npm token can reach. The affected packages collectively account for tens of millions of weekly downloads. New packages are appearing in real time, and Socket team will keep on updating the list.

The evidence indicates the maintainer account (Jaredwray) was compromised and used to publish across two package families.

Read more on Socket Security Blog