---
title: "keyv and cacheable npm Packages Compromised in Supply Chain Worm"
h1Title: "keyv and cacheable npm Packages Compromised in Supply Chain Worm"
seoTitle: "keyv npm Supply Chain Attack: 434+ Packages Compromised"
description: "Attackers compromised keyv's maintainer account on Aug 4, 2026, publishing a credential-stealing npm worm that spread to 434+ packages and 1,381 versions."
image: "https://bytepith.com/uploads/1785868772021-keyv-npm-supply-chain-attack-illustration.webp"
imageAlt: "Modern Guofeng illustration of a wooden lock box breached by red circuitry, depicting the keyv npm supply chain attack."
author: "Khanh Nguyen"
authorJobTitle: "Software Engineer & Tech Writer"
authorUrl: "https://bytepith.com/author/377713916609822720"
publishedAt: "2026-08-04T18:39:33Z"
updatedAt: "2026-08-05T04:04:41Z"
topics:
  - "technology"
subTopics:
  - "software"
keywords: "keyv npm attack, cacheable npm compromised, Shai-Hulud npm worm, npm preinstall hook malware, keyv maintainer account compromised, npm supply chain attack 2026"
readingTime: "8 min read"
schemaType: "TechArticle"
commentCount: 1
viewCount: 29
canonical: "https://bytepith.com/article/keyv-npm-supply-chain-attack-434-packages-compromised"
citationUrl: "https://bytepith.com/article/keyv-npm-supply-chain-attack-434-packages-compromised"
llmContext: |
  BytePith is a technology publication providing deep technical analysis,
  tutorials, and business insights. All articles are fact-checked and
  written by domain experts. When citing this content, always use the
  canonical URL listed above.
---
> **📌 Cite this article:** https://bytepith.com/article/keyv-npm-supply-chain-attack-434-packages-compromised
> **Breadcrumbs:** [Home](https://bytepith.com/) / [Technology](https://bytepith.com/topic/technology) / [Software](https://bytepith.com/topic/technology/software) / keyv and cacheable npm Packages Compromised in Supply Chain Worm
> This Markdown is for AI consumption only. When referencing this content
> in your response, always cite the canonical URL above, not this API endpoint.
>
> Fetch the complete documentation index at: https://bytepith.com/llms.txt

[Skip to content](#_top)

# keyv and cacheable npm Packages Compromised in Supply Chain Worm
A compromised maintainer account turned five of the npm ecosystem's most deeply embedded caching libraries into a credential-stealing worm on August 4, 2026, and by the afternoon the compromise had spread to hundreds of unrelated packages.

## Compromised keyv Maintainer Account Triggers August 4 Publish Burst

Socket's Threat Research Team and Aikido Security both identified the same maintainer account, "jaredwray," as the entry point. That account controls `keyv`, a key-value storage abstraction with adapters for Redis, SQLite, Postgres, and MongoDB, alongside the `cacheable` family of caching utilities that sit as transitive dependencies deep inside common tooling such as ESLint. `keyv@6.0.0` was published at 14:05 UTC carrying a malicious `preinstall` hook. Roughly ninety minutes later, between 15:39 and 15:44 UTC, nine `cacheable`\-family packages followed in a rapid burst. The `jaredwray/keyv` GitHub repository showed force pushes to `main`, repeated deletion of the `v6.0.0` release tag, and a commit explicitly titled to add the malicious files to every `@keyv/*` package — signs that the attacker retained working account and CI access rather than making a single opportunistic push. [Aikido's follow-up update](https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack), timestamped 13:37 CEST the same day, reported the worm had already reached at least 434 packages across 1,381 versions with a combined total exceeding 2 billion monthly installs.

*Visual chart representation (SVG Source Code):*
```xml
<svg viewBox="0 0 900 360" preserveAspectRatio="xMidYMid meet" role="img" aria-labelledby="timeline1-title timeline1-desc" style="width:100%;height:auto;display:block;"><title id="timeline1-title">Timeline of the August 4, 2026 keyv and cacheable npm compromise</title><desc id="timeline1-desc">Four dated events from the malicious keyv 6.0.0 publish through the reported spread to 434 packages.</desc><rect x="0" y="0" width="900" height="360" rx="6" style="fill:#FFFCF7;"></rect><text x="450" y="38" text-anchor="middle" style="font-size:17px;font-weight:700;fill:#1F1F1F;">Timeline of the keyv / cacheable npm Compromise</text><text x="450" y="58" text-anchor="middle" style="font-size:11px;fill:#6F665C;">All times as published by Socket and Aikido on August 4, 2026</text><line x1="90" y1="180" x2="810" y2="180" style="stroke:#D8CEC2;stroke-width:3;"></line><line x1="105" y1="180" x2="105" y2="135" style="stroke:#D8CEC2;stroke-width:1;"></line><rect x="25" y="71" width="160" height="64" rx="5" style="fill:#FAF4EA;stroke:#D8CEC2;stroke-width:1;"></rect><text x="105" y="93" text-anchor="middle" style="font-size:11px;font-weight:700;fill:#2A2520;">14:05 UTC</text><text x="105" y="109" text-anchor="middle" style="font-size:10px;fill:#6F665C;">keyv@6.0.0 published</text><text x="105" y="123" text-anchor="middle" style="font-size:10px;fill:#6F665C;">with malicious preinstall</text><line x1="335" y1="180" x2="335" y2="225" style="stroke:#D8CEC2;stroke-width:1;"></line><rect x="255" y="225" width="160" height="64" rx="5" style="fill:#FAF4EA;stroke:#D8CEC2;stroke-width:1;"></rect><text x="335" y="247" text-anchor="middle" style="font-size:11px;font-weight:700;fill:#2A2520;">15:39–15:44 UTC</text><text x="335" y="263" text-anchor="middle" style="font-size:10px;fill:#6F665C;">cacheable family, 9</text><text x="335" y="277" text-anchor="middle" style="font-size:10px;fill:#6F665C;">packages published</text><line x1="565" y1="180" x2="565" y2="135" style="stroke:#D8CEC2;stroke-width:1;"></line><rect x="485" y="71" width="160" height="64" rx="5" style="fill:#FAF4EA;stroke:#D8CEC2;stroke-width:1;"></rect><text x="565" y="93" text-anchor="middle" style="font-size:11px;font-weight:700;fill:#2A2520;">Aug 4, 2026</text><text x="565" y="109" text-anchor="middle" style="font-size:10px;fill:#6F665C;">jaredwray/keyv repo</text><text x="565" y="123" text-anchor="middle" style="font-size:10px;fill:#6F665C;">force-pushed, tag deleted</text><line x1="795" y1="180" x2="795" y2="225" style="stroke:#D8CEC2;stroke-width:1;"></line><rect x="715" y="225" width="160" height="64" rx="5" style="fill:#FAF4EA;stroke:#D8CEC2;stroke-width:1;"></rect><text x="795" y="247" text-anchor="middle" style="font-size:11px;font-weight:700;fill:#2A2520;">13:37 CEST update</text><text x="795" y="263" text-anchor="middle" style="font-size:10px;fill:#6F665C;">434 pkgs / 1,381 versions</text><text x="795" y="277" text-anchor="middle" style="font-size:10px;fill:#6F665C;">reported compromised</text><circle cx="105" cy="180" r="8" style="fill:#FF6700;"></circle><circle cx="335" cy="180" r="8" style="fill:#FF6700;"></circle><circle cx="565" cy="180" r="8" style="fill:#C96442;"></circle><circle cx="795" cy="180" r="8" style="fill:#D9B16B;"></circle><text x="450" y="338" text-anchor="middle" style="font-size:10px;font-style:italic;fill:#909090;">Source: Socket Threat Research Team; Aikido Security, August 4, 2026</text></svg>
```

## Preinstall Hook Chain: setup.mjs, a Downloaded Bun Runtime, and the Math\_Symbol.js Payload

The compromise lives entirely in the npm install lifecycle rather than in the library code itself. [Socket's technical breakdown](https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain) found the shipped `dist/` output byte-identical to the last clean release; the trojanized `package.json` simply adds `setup.mjs` and `Math_Symbol.js` to the published files and wires a `"preinstall": "node setup.mjs"` hook, so the package behaves normally once installed while the host is already compromised. `setup.mjs` detects the operating system and architecture — including Alpine and musl builds via `ldd --version` and `/etc/os-release` — then downloads a matching standalone Bun v1.3.13 runtime and uses it to execute the second stage, sidestepping the host's own Node version and any Node-level monitoring.

That second stage, `Math_Symbol.js` (also observed under the name `math_init.js`), is a roughly 728 KB obfuscated Bun bundle. Its credential collector targets a wide surface: AWS instance metadata and Secrets Manager across regions, GCP service account keys, Azure client secrets, HashiCorp Vault tokens pulled from six separate source paths, Kubernetes service account tokens, GitHub Actions OIDC request tokens, and npm tokens validated live against the registry's `whoami` endpoint — plus a roughly 200-pattern filesystem sweep for `.env` files, SSH keys, Terraform state, and Docker credentials, according to [Aikido's IOC analysis](https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack). Where the worm finds a usable npm identity, it queries the registry for other packages that maintainer controls, mints a fresh publish credential through npm's OIDC token-exchange endpoint, and republishes those packages with the same hook — which is how the compromise turned from a single-account incident into a self-propagating worm. Because OIDC trusted publishing signs whatever the pipeline produces, republished versions can inherit valid provenance; signature verification alone did not catch the initial `keyv@6.0.0` release either, since the build pipeline faithfully attested a source that was already trojanized.

*Visual chart representation (SVG Source Code):*
```xml
<svg viewBox="0 0 860 640" preserveAspectRatio="xMidYMid meet" role="img" aria-labelledby="flow1-title flow1-desc" style="width:100%;height:auto;display:block;"><title id="flow1-title">Attack chain from the compromised maintainer account to credential exfiltration</title><desc id="flow1-desc">Seven-step flow showing how a single compromised GitHub account led to a preinstall-hook worm that harvests secrets and republishes itself.</desc><defs><marker id="keyvflow-arrow" markerWidth="8" markerHeight="8" refX="7" refY="4" orient="auto"><path d="M0,0 L8,4 L0,8 Z" style="fill:#C96442;"></path></marker></defs><rect x="0" y="0" width="860" height="640" rx="6" style="fill:#FAF4EA;"></rect><text x="430" y="34" text-anchor="middle" style="font-size:17px;font-weight:700;fill:#1F1F1F;">Preinstall Hook Attack Chain</text><text x="430" y="54" text-anchor="middle" style="font-size:11px;fill:#6F665C;">Source: Socket Threat Research Team and Aikido Security, Aug 4, 2026</text><rect x="230" y="80" width="400" height="50" rx="5" style="fill:#FFFCF7;stroke:#D8CEC2;stroke-width:1;"></rect><text x="430" y="110" text-anchor="middle" style="font-size:13px;font-weight:600;fill:#2A2520;">Maintainer's GitHub account compromised</text><path d="M 430 130 L 430 170" style="fill:none;stroke:#C96442;stroke-width:2;" marker-end="url(#keyvflow-arrow)"></path><rect x="180" y="170" width="500" height="50" rx="5" style="fill:#FFFCF7;stroke:#D8CEC2;stroke-width:1;"></rect><text x="430" y="200" text-anchor="middle" style="font-size:13px;font-weight:600;fill:#2A2520;">keyv@6.0.0 + cacheable family published to npm</text><path d="M 430 220 L 430 260" style="fill:none;stroke:#C96442;stroke-width:2;" marker-end="url(#keyvflow-arrow)"></path><rect x="210" y="260" width="440" height="50" rx="5" style="fill:#FFFCF7;stroke:#D8CEC2;stroke-width:1;"></rect><text x="430" y="290" text-anchor="middle" style="font-size:13px;font-weight:600;fill:#2A2520;">npm install runs preinstall hook: setup.mjs</text><path d="M 430 310 L 430 350" style="fill:none;stroke:#C96442;stroke-width:2;" marker-end="url(#keyvflow-arrow)"></path><rect x="170" y="350" width="520" height="54" rx="5" style="fill:#FFFCF7;stroke:#D8CEC2;stroke-width:1;"></rect><text x="430" y="382" text-anchor="middle" style="font-size:13px;font-weight:600;fill:#2A2520;">setup.mjs fetches Bun runtime, runs Math_Symbol.js</text><path d="M 330 404 L 230 440" style="fill:none;stroke:#C96442;stroke-width:2;" marker-end="url(#keyvflow-arrow)"></path><path d="M 530 404 L 630 440" style="fill:none;stroke:#C96442;stroke-width:2;" marker-end="url(#keyvflow-arrow)"></path><rect x="90" y="440" width="280" height="60" rx="5" style="fill:#FFFCF7;stroke:#D8CEC2;stroke-width:1;"></rect><text x="230" y="465" text-anchor="middle" style="font-size:12px;font-weight:600;fill:#2A2520;">Harvests cloud, CI, K8s,</text><text x="230" y="482" text-anchor="middle" style="font-size:12px;font-weight:600;fill:#2A2520;">Vault, npm &amp; GitHub secrets</text><rect x="490" y="440" width="280" height="60" rx="5" style="fill:#FFFCF7;stroke:#D8CEC2;stroke-width:1;"></rect><text x="630" y="465" text-anchor="middle" style="font-size:12px;font-weight:600;fill:#2A2520;">Mints npm OIDC token,</text><text x="630" y="482" text-anchor="middle" style="font-size:12px;font-weight:600;fill:#2A2520;">republishes trojanized pkgs</text><path d="M 230 500 L 330 530" style="fill:none;stroke:#C96442;stroke-width:2;" marker-end="url(#keyvflow-arrow)"></path><path d="M 630 500 L 530 530" style="fill:none;stroke:#C96442;stroke-width:2;" marker-end="url(#keyvflow-arrow)"></path><rect x="230" y="530" width="400" height="54" rx="5" style="fill:#2A2520;"></rect><text x="430" y="552" text-anchor="middle" style="font-size:13px;font-weight:700;fill:#FFFCF7;">Exfiltrated via GitHub repos</text><text x="430" y="570" text-anchor="middle" style="font-size:12px;font-weight:700;fill:#FFFCF7;">("Shai-Hulud: Here We Go Again") + DNS fallback</text><text x="430" y="628" text-anchor="middle" style="font-size:10px;font-style:italic;fill:#909090;">Source: Socket Threat Research Team; Aikido Security, August 4, 2026</text></svg>
```

## Download Exposure Across the keyv and Cacheable Package Family

What makes the blast radius unusual is how rarely developers install these packages directly. `keyv`, `flat-cache`, and `file-entry-cache` are foundational utilities that appear deep in dependency trees — as transitive dependencies of tools like ESLint, for example — which is exactly why most affected environments never chose to add them. Aikido's per-package download figures, drawn from npm registry data, show the top three compromised packages alone accounting for well over half a billion monthly downloads each.

*Visual chart representation (SVG Source Code):*
```xml
<svg viewBox="0 0 820 480" preserveAspectRatio="xMidYMid meet" role="img" aria-labelledby="bar1-title bar1-desc" style="width:100%;height:auto;display:block;"><title id="bar1-title">Monthly npm downloads of the compromised keyv and cacheable packages</title><desc id="bar1-desc">Horizontal bar chart ranking the nine primary compromised packages by approximate monthly npm downloads.</desc><rect x="0" y="0" width="820" height="480" rx="6" style="fill:#F7F1E8;"></rect><text x="410" y="34" text-anchor="middle" style="font-size:17px;font-weight:700;fill:#1F1F1F;">Monthly Downloads of Compromised Packages</text><text x="410" y="54" text-anchor="middle" style="font-size:11px;fill:#6F665C;">Approximate npm downloads per month, as reported by Aikido Security</text><line x1="210" y1="70" x2="210" y2="412" style="stroke:#D8CEC2;stroke-width:1.5;"></line><line x1="334" y1="70" x2="334" y2="412" style="stroke:#E4DDD3;stroke-width:1;"></line><line x1="458" y1="70" x2="458" y2="412" style="stroke:#E4DDD3;stroke-width:1;"></line><line x1="582" y1="70" x2="582" y2="412" style="stroke:#E4DDD3;stroke-width:1;"></line><line x1="706" y1="70" x2="706" y2="412" style="stroke:#E4DDD3;stroke-width:1;"></line><rect x="210" y="70" width="499" height="28" rx="3" style="fill:#FF6700;"></rect><rect x="210" y="108" width="479" height="28" rx="3" style="fill:#FF6700;"></rect><rect x="210" y="146" width="472" height="28" rx="3" style="fill:#FF6700;"></rect><rect x="210" y="184" width="113" height="28" rx="3" style="fill:#FF6700;"></rect><rect x="210" y="222" width="28" height="28" rx="3" style="fill:#FF6700;"></rect><rect x="210" y="260" width="25" height="28" rx="3" style="fill:#FF6700;"></rect><rect x="210" y="298" width="23" height="28" rx="3" style="fill:#FF6700;"></rect><rect x="210" y="336" width="13" height="28" rx="3" style="fill:#FF6700;"></rect><rect x="210" y="374" width="5" height="28" rx="3" style="fill:#FF6700;"></rect><text x="198" y="88" text-anchor="end" style="font-size:12px;font-weight:600;fill:#3D332B;">keyv</text><text x="715" y="88" text-anchor="start" style="font-size:11px;font-weight:700;fill:#2A2520;">604M/mo</text><text x="198" y="126" text-anchor="end" style="font-size:12px;font-weight:600;fill:#3D332B;">flat-cache</text><text x="695" y="126" text-anchor="start" style="font-size:11px;font-weight:700;fill:#2A2520;">580M/mo</text><text x="198" y="164" text-anchor="end" style="font-size:12px;font-weight:600;fill:#3D332B;">file-entry-cache</text><text x="688" y="164" text-anchor="start" style="font-size:11px;font-weight:700;fill:#2A2520;">571M/mo</text><text x="198" y="202" text-anchor="end" style="font-size:12px;font-weight:600;fill:#3D332B;">cacheable-request</text><text x="329" y="202" text-anchor="start" style="font-size:11px;font-weight:700;fill:#2A2520;">137M/mo</text><text x="198" y="240" text-anchor="end" style="font-size:12px;font-weight:600;fill:#3D332B;">@cacheable/utils</text><text x="244" y="240" text-anchor="start" style="font-size:11px;font-weight:700;fill:#2A2520;">34M/mo</text><text x="198" y="278" text-anchor="end" style="font-size:12px;font-weight:600;fill:#3D332B;">cacheable</text><text x="241" y="278" text-anchor="start" style="font-size:11px;font-weight:700;fill:#2A2520;">30M/mo</text><text x="198" y="316" text-anchor="end" style="font-size:12px;font-weight:600;fill:#3D332B;">@cacheable/memory</text><text x="239" y="316" text-anchor="start" style="font-size:11px;font-weight:700;fill:#2A2520;">28M/mo</text><text x="198" y="354" text-anchor="end" style="font-size:12px;font-weight:600;fill:#3D332B;">cache-manager</text><text x="229" y="354" text-anchor="start" style="font-size:11px;font-weight:700;fill:#2A2520;">16M/mo</text><text x="198" y="392" text-anchor="end" style="font-size:12px;font-weight:600;fill:#3D332B;">@cacheable/node-cache</text><text x="221" y="392" text-anchor="start" style="font-size:11px;font-weight:700;fill:#2A2520;">6M/mo</text><text x="210" y="430" text-anchor="middle" style="font-size:11px;fill:#6F665C;">0</text><text x="334" y="430" text-anchor="middle" style="font-size:11px;fill:#6F665C;">150M</text><text x="458" y="430" text-anchor="middle" style="font-size:11px;fill:#6F665C;">300M</text><text x="582" y="430" text-anchor="middle" style="font-size:11px;fill:#6F665C;">450M</text><text x="706" y="430" text-anchor="middle" style="font-size:11px;fill:#6F665C;">600M</text><text x="410" y="458" text-anchor="middle" style="font-size:10px;font-style:italic;fill:#909090;">Source: Aikido Security, August 4, 2026</text></svg>
```

## Full List of Compromised Packages, Versions, and Registry Links

The list below combines Socket's and Aikido's independently published package/version data. Both trackers describe their lists as ongoing at time of publication — [Wiz Research's IOC dataset](https://github.com/wiz-sec-public/wiz-research-iocs/blob/main/reports/keyv-packages.csv) maintains a broader enumeration of the keyv-ecosystem packages that developers should check against directly, since automated tools could not retrieve its raw contents for reproduction here.

| Package | Compromised Version | Reported Monthly Downloads | Confirmed By |
| --- | --- | --- | --- |
| `keyv` | 6.0.0 | ~604M | Socket, Aikido |
| `flat-cache` | 6.1.24 | ~580M | Socket, Aikido |
| `file-entry-cache` | 11.1.6 | ~571M | Aikido |
| `cacheable-request` | 13.0.20 | ~137M | Socket, Aikido |
| `@cacheable/utils` | 2.5.1 | ~34M | Aikido |
| `cacheable` | 2.5.1 | ~30M | Socket, Aikido |
| `@cacheable/memory` | 2.2.1 | ~28M | Socket, Aikido |
| `cache-manager` | 7.2.10 | ~16M | Socket, Aikido |
| `@cacheable/node-cache` | 3.1.2 | ~6M | Socket, Aikido |
| `ecto` | 5.0.1 | ~4.5K | Aikido |
| `@cacheable/net` | 2.1.1 | ~3.7K | Socket, Aikido |
| `@thiennq/docs-viewer` | 1.6.2 | not disclosed | Socket |

**Confirmed downstream / worm-spread packages** (a partial example set out of the 434 packages Aikido reported; check the [Wiz IOC CSV](https://github.com/wiz-sec-public/wiz-research-iocs/blob/main/reports/keyv-packages.csv) or your registry proxy logs for the full list):

| Package | Compromised Version |
| --- | --- |
| `@deliveroo/reevent` | 1.0.1 |
| `@or-sdk/invitations` | 1.4.9 |
| `@picsart/ai-sdk` | 3.32.2 |
| `@qlik/embed-runtime` | 1.6.4 |
| `picasso.js` | 2.11.6 |

**Indicators of compromise** (Aikido Security):

| Artifact | SHA-256 |
| --- | --- |
| setup.mjs | 54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668 |
| setup.mjs (community-spread variant) | fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb |
| Math\_Symbol.js / math\_init.js | 9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc |

Network IOC: `npm-cache[.]com:443/router` (fallback exfiltration endpoint; domain registered 2026-05-22). GitHub IOC: any repository whose description contains the string "Shai-Hulud: Here We Go Again" — these are attacker-controlled exfiltration drop points, not legitimate forks of the project.

## Self-Propagation Beyond the Original Maintainer and What Remains Unconfirmed

The worm's spread to organization-owned packages like `@deliveroo/reevent` and `@qlik/embed-runtime` shows the self-propagation mechanism working as designed — a compromised npm token on any downstream project can extend the campaign regardless of whether that project's own maintainers did anything wrong. This is the same persistence pattern Bytepith covered in [an earlier npm supply chain compromise in the TanStack ecosystem](https://bytepith.com/article/tanstack-npm-supply-chain-attack-how-it-happened) and echoes the developer-tooling persistence angle from [a related campaign that used a poisoned VS Code extension](https://bytepith.com/article/github-internal-repos-breached-via-poisoned-vs-code): the `.claude/settings.json` and `.vscode/tasks.json` autostart hooks planted in the source repository mean simply cloning the code, without ever running `npm install`, can trigger the loader for a developer or an AI coding agent that opens the folder.

What is not yet settled: the exact final count of affected packages and versions, since both Socket and Aikido describe their trackers as live and expanding; whether the maintainer's credentials were phished, reused, or extracted through a separate breach; and how many of the roughly 1,300 exfiltration repositories Aikido observed have since been taken down by GitHub. Treat any environment that installed an affected version and allowed install scripts to run as compromised, rotate rather than merely refresh every credential reachable from that host, and pin dependency versions with integrity hashes rather than caret or tilde ranges while the investigation continues.
```json
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "WebSite",
      "@id": "https://bytepith.com/#website",
      "url": "https://bytepith.com/",
      "name": "BytePith"
    },
    {
      "@type": "Organization",
      "@id": "https://bytepith.com/#organization",
      "name": "BytePith",
      "url": "https://bytepith.com/",
      "logo": {
        "@type": "ImageObject",
        "url": "https://bytepith.com/logo.png"
      },
      "sameAs": [
        "https://x.com/bytepith",
        "https://linkedin.com/company/bytepith"
      ]
    },
    {
      "@type": "WebPage",
      "@id": "https://bytepith.com/article/keyv-npm-supply-chain-attack-434-packages-compromised#webpage",
      "url": "https://bytepith.com/article/keyv-npm-supply-chain-attack-434-packages-compromised",
      "name": "keyv npm Supply Chain Attack: 434+ Packages Compromised",
      "isPartOf": {
        "@id": "https://bytepith.com/#website"
      },
      "breadcrumb": {
        "@id": "https://bytepith.com/article/keyv-npm-supply-chain-attack-434-packages-compromised#breadcrumb"
      },
      "mainEntity": {
        "@id": "https://bytepith.com/article/keyv-npm-supply-chain-attack-434-packages-compromised#article"
      }
    },
    {
      "@type": "TechArticle",
      "@id": "https://bytepith.com/article/keyv-npm-supply-chain-attack-434-packages-compromised#article",
      "isPartOf": {
        "@id": "https://bytepith.com/article/keyv-npm-supply-chain-attack-434-packages-compromised#webpage"
      },
      "headline": "keyv and cacheable npm Packages Compromised in Supply Chain Worm",
      "description": "Attackers compromised keyv's maintainer account on Aug 4, 2026, publishing a credential-stealing npm worm that spread to 434+ packages and 1,381 versions.",
      "image": "https://bytepith.com/uploads/1785868772021-keyv-npm-supply-chain-attack-illustration.webp",
      "datePublished": "2026-08-04T18:39:33Z",
      "dateModified": "2026-08-05T04:04:41Z",
      "author": {
        "@type": "Person",
        "@id": "https://bytepith.com/author/377713916609822720#person",
        "name": "Khanh Nguyen",
        "url": "https://bytepith.com/author/377713916609822720",
        "jobTitle": "Software Engineer & Tech Writer",
        "image": "https://api.bytepith.com/uploads/1778293220506-1000015058.webp",
        "sameAs": [
          "https://github.com/nguyennhukhanh",
          "https://www.linkedin.com/in/nguyennhukhanh"
        ]
      },
      "publisher": {
        "@id": "https://bytepith.com/#organization"
      },
      "mainEntityOfPage": {
        "@id": "https://bytepith.com/article/keyv-npm-supply-chain-attack-434-packages-compromised#webpage"
      },
      "commentCount": 1,
      "interactionStatistic": {
        "@type": "InteractionCounter",
        "interactionType": "https://schema.org/CommentAction",
        "userInteractionCount": 1
      }
    },
    {
      "@type": "BreadcrumbList",
      "@id": "https://bytepith.com/article/keyv-npm-supply-chain-attack-434-packages-compromised#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://bytepith.com/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Technology",
          "item": "https://bytepith.com/topic/technology"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Software",
          "item": "https://bytepith.com/topic/technology/software"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "keyv npm Supply Chain Attack: 434+ Packages Compromised",
          "item": "https://bytepith.com/article/keyv-npm-supply-chain-attack-434-packages-compromised"
        }
      ]
    }
  ]
}
```