SlowMist: Keyv/Cacheable Ecosystem Suffers Large-Scale npm Supply Chain Attack, with Over 2000 Malicious Versions
August 5th, SlowMist announced a large-scale npm supply chain attack affecting the Keyv/Cacheable ecosystem. The attacker has released over 2000 malicious package versions in the ecosystem, including keyv@6.0.0.
Keyv is a widely used key-value storage abstraction supporting backends such as Redis, SQLite, PostgreSQL, MongoDB, with a weekly download volume of about 127 million, posing a significant downstream supply chain risk.
This attack is highly similar to the previous Shai-Hulud npm worm activity, demonstrating strong automation and propagation capabilities. Potential actions include credential theft, external environment variable exfiltration, CI/CD key leakage, remote payload delivery, and lateral movement through infected development environments.
The security team is advised to promptly identify and remove the affected versions, upgrade to verified secure versions, check dependency lock files and build logs, monitor for abnormal outbound connections, and rotate potentially exposed credentials. If a compromise is suspected, rebuilding from a trusted source is recommended.