Threat reportSupply ChainTL-2026-1861
Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware)
Keyv and Cacheable npm Supply Chain Attack via Compromised (TL-2026-1861), also tracked as Keyv-Cacheable Supply Chain Compromise, is a critical-severity supply-chain compromise, first published 2026-08-04 and last reviewed 2026-10-04. It is attributed to TeamPCP with medium confidence, affects npm (Node Package Manager) keyv, maps to 42 MITRE ATT&CK techniques (T1003.007, T1005, T1008), and is covered by 9 detection rules and 62 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 42MITRE ATT&CK
- Actors
- 1TeamPCP
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 62Indicators of compromise
Key facts for TL-2026-1861
- Threat ID
- TL-2026-1861
- Also known as
- Keyv-Cacheable Supply Chain Compromise, Shai-Hulud Keyv Campaign, Jared Wray Maintainer Account Hijack
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- TeamPCP
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, cloud-services, financial-services, artificial-intelligence, health
- Target regions
- North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 62
- Updates
- 2026-10-04 · 2 updates · revalidated 2× · latest source
Malware and tooling in Keyv and Cacheable npm Supply Chain Attack via Compromised
Malware and tooling: Shai-Hulud, Ethereum JSON-RPC
How Keyv and Cacheable npm Supply Chain Attack via Compromised works
Attackers compromised the GitHub maintainer account of Jared Wray (keyv/cacheable ecosystem) and published malicious versions across at least 868 npm packages (1,381 versions, over 2 billion combined monthly installs) carrying a Shai-Hulud-family payload that steals cloud credentials, infrastructure secrets, developer credentials, AI configurations, cryptocurrency wallets, and CI/CD pipeline secrets, using Ethereum RPC endpoints for C2 communications.
On August 4, 2026, Wiz Research disclosed an ongoing supply chain attack targeting the npm ecosystem through the compromise of Jared Wray's GitHub maintainer account, which governed the highly popular keyv and cacheable package families. The attacker published malicious versions (keyv@6.0.0, cacheable-request@13.0.20, cache-manager@7.2.10, @cacheable/utils@2.5.1, and dozens more across @ornikar/*, @qlik/*, picasso-plugin-*, and other packages) containing an identical obfuscated payload delivered via install-time hooks. The payload is a descendant of the Shai-Hulud malware family and shares code-level similarities with the prior TeamPCP and antv supply chain campaigns, but introduces a novel C2 mechanism: Ethereum JSON-RPC infrastructure (NodeReal, GetBlock, LlamaRPC) as a communication channel, representing a significant evolution in the malware's operational security posture. On execution, the payload enumerates the host environment (identifying build runners, cloud platforms, and CI/CD context), harvests credentials from cloud metadata services (~/.aws, ~/.gcp, ~/.azure), environment variables, configuration files, developer SSH keys, GitHub tokens, Kubernetes configurations, Terraform state, AI/ML framework configs (e.g. OpenAI API keys, Hugging Face tokens), and cryptocurrency wallet files. Exfiltrated data is transmitted to npm-cache[.]com (Cloudflare-hosted), while Ethereum RPC endpoints serve as C2 relay infrastructure. A distinctive attribution string — 'IfYouBlockThisAPIKeyItWillCrashTheLiveProductionServersOfAllThirdPartyClients' — was embedded in the payload. The malicious versions lacked build provenance. The npm registry subsequently deprecated the identified malicious versions. Wiz Research's investigation remains active, with newly identified packages being added as analysis continues. The attack's scale — affecting 868 packages spanning 1,381 versions with over 2 billion monthly npm installs across the dependency graph — ranks among the largest supply chain compromises of the npm ecosystem to date.
MITRE ATT&CK techniques used in TL-2026-1861
Credential Access
T1003.007 OS Credential Dumping; T1528 Steal Application Access Token; T1552 Unsecured Credentials; T1552.001 Unsecured Credentials; T1552.005 Unsecured Credentials; T1555 Credentials from Password Stores; T1606 Forge Web Credentials
Collection
T1005 Data from Local System; T1119 Automated Collection; T1560 Archive Collected Data
Command and Control
T1008 Fallback Channels; T1071 Application Layer Protocol; T1071.001 Application Layer Protocol; T1090 Proxy; T1102.001 Web Service; T1568 Dynamic Resolution; T1573 Encrypted Channel
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1070.004 Indicator Removal
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service; T1567.001 Exfiltration Over Web Service
Execution
T1059 Command and Scripting Interpreter; T1059.007 Command and Scripting Interpreter; T1203 Exploitation for Client Execution; T1204 User Execution
Initial Access
T1078 Valid Accounts; T1195 Supply Chain Compromise; T1195.002 Supply Chain Compromise: Compromise Software Supply Chain; T1199 Trusted Relationship
Discovery
T1082 System Information Discovery; T1087 Account Discovery; T1580 Cloud Infrastructure Discovery
command-and-control
Impact
T1485 Data Destruction; T1496 Resource Hijacking
Persistence
T1546 Event Triggered Execution; T1547 Boot or Logon Autostart Execution; T1554 Compromise Host Software Binary
Resource Development
Affected products and versions in Keyv and Cacheable npm Supply Chain Attack via Compromised
- npm (Node Package Manager) — keyv
Vulnerable versions: 5.5.2; 5.5.3; 5.5.5; 5.6.0; 6.0.0-alpha.1; 6.0.0-alpha.2; 6.0.0-rc.1; 6.0.0
Fixed in: 6.0.0-beta.4+; 5.5.1 or earlier - npm (Node Package Manager) — cacheable-request
Vulnerable versions: 13.0.20
Fixed in: 13.0.19 or earlier - npm (Node Package Manager) — cache-manager
Vulnerable versions: 7.2.10
Fixed in: 7.2.9 or earlier - npm (Node Package Manager) — @cacheable/utils
Vulnerable versions: 2.5.1
Fixed in: 2.5.0 or earlier - npm (Node Package Manager) — @ornikar/* (27 packages)
Vulnerable versions: Multiple versions (babel presets, eslint configs, repo configs, etc.)
Fixed in: Pre-August 2026 versions - npm (Node Package Manager) — @qlik/* (4 packages)
Vulnerable versions: @qlik/embed-react@2.5.3; @qlik/embed-runtime@1.6.4; @qlik/embed-web-components@1.7.3; @qlik/runtime-module-loader@1.5.1
Fixed in: Pre-August 2026 versions - npm (Node Package Manager) — picasso-plugin-*
Vulnerable versions: picasso-plugin-hammer@2.11.6; picasso-plugin-q@2.11.6
Fixed in: Pre-August 2026 versions - npm (Node Package Manager) — @nebula.js/nucleus
Vulnerable versions: 0.5.1
Fixed in: 0.5.0 or earlier - npm (Node Package Manager) — @hubsync/web-sdk-react
Vulnerable versions: 6.3.7
Fixed in: 6.3.6 or earlier
Remediation for Keyv and Cacheable npm Supply Chain Attack via Compromised
Patches
- Pin keyv to versions <5.5.2 or >=6.0.0-beta.4 (verify integrity SHA)
- Pin cacheable-request to versions <13.0.20 or >=14.0.0
- Pin cache-manager to versions <7.2.10 or >=8.0.0
- Use overrides/resolutions in package.json to force clean versions across transitive dependencies
Immediate actions
- Identify and remove affected package versions (keyv@6.0.0, cacheable-request@13.0.20, cache-manager@7.2.10, @cacheable/utils@2.5.1, and all listed @ornikar/*, @qlik/* malicious versions) from dev, build, and CI/CD environments
- Scan lock files (package-lock.json, yarn.lock, pnpm-lock.yaml) for all 1,381 malicious package versions across 868 packages
- Check for presence of /tmp/bun-dl-* directories and node_modules/keyv/Math_Symbol.js on any system that ran npm install on affected versions
- Rotate ALL exposed credentials: cloud provider API keys, GitHub tokens, SSH keys, Kubernetes configurations, Terraform state credentials, AI/ML API keys, and any stored secrets in affected environments
- Block network traffic to npm-cache[.]com, eth-mainnet.nodereal[.]io, go.getblock[.]io, and eth.llamarpc[.]com at perimeter firewalls and EDR
Workarounds
- Disable npm install scripts globally (npm config set ignore-scripts true) until package inventory is clean
- Audit all third-party packages that transitively pull in keyv/cacheable ecosystem
- Monitor for connections to ETH RPC endpoints from non-crypto application code — this is a strong indicator of compromise
Longer-term hardening
- Treat any system that installed affected packages as potentially compromised — rebuild from clean artifacts
- Enable dependency allowlisting and package integrity verification in CI/CD pipelines
- Implement provenance-based trust (require npm packages to carry valid provenance attestations)
- Use npm audit and Socket.dev/Shoulder.dev-style automated scanning for install-time behavioral analysis
- Add network monitoring for unexpected ETH RPC traffic from build/CI/CD environments
- Enable staged publishing and trusted publisher bindings with hardware-bound OIDC tokens to prevent single-account compromise from affecting the full package surface
Weaknesses (CWE) in Keyv and Cacheable npm Supply Chain Attack via Compromised
Timeline of Keyv and Cacheable npm Supply Chain Attack via Compromised
Showing the 20 most recent tracked events.
- Mini Shai-Hulud (TeamPCP) compromises @tanstack/*, @antv/* via GitHub Actions cache poisoning + OIDC token extraction; 639 malicious versions across 323 packages published with valid SLSA provenance — first-ever malware with valid provenance attestation
- TeamPCP open-sources the Shai-Hulud worm code on GitHub under an MIT license ('Shai-Hulud: Open Sourcing The Carnage'), making payload-lineage attribution of later campaigns unreliable.
- @antv ecosystem compromised via the 'atool' npm account — 637 malicious versions across 317 packages published in 22 minutes.
- C2 domain npm-cache[.]com (104.21.35.216) registered ahead of the campaign.
- Prior Shai-Hulud-family wave 'Miasma' compromises 32+ @redhat-cloud-services packages using a compromised Red Hat employee GitHub account with valid SLSA provenance.
- GitHub maintainer account of Jared Wray (keyv/cacheable ecosystem creator) compromised by threat actors — exact method and date of initial breach unknown; investigation ongoing
- keyv@6.0.0-rc.1 published from compromised account; release candidate triggers initial scanning by security monitoring platforms
- Socket verifies 2,251 poisoned versions across 452 packages; 546 public exfiltration repositories ('Shai-Hulud: Here We Go Again') created on the day.
- The StringListStore Ethereum contract, initially configured with three domains (npm-cache.com, pypi-get.com, js-mirror.com), is updated to return only npm-cache.com.
- ~09:39 UTC: payload copied across 19 @keyv/* workspace packages; worm then spreads to nine unrelated organizations, one every 2-7 minutes.
- npm registry rolls back some malicious versions from 'latest' (flat-cache to 6.1.23, cacheable-request to 13.0.19, cache-manager to 7.2.9); Snyk publishes advisory SNYK-JS-KEYV-18515941 (exploit maturity 'Attacked').
- Wiz reports additional compromised packages at 13:45 UTC, adds Ethereum smart-contract C2 analysis at 15:00 UTC, and confirms 400+ distinct infected packages at 15:25 UTC.
- Worm self-propagates using stolen npm tokens with bypass_2fa=true and package-write permission, republishing malicious versions across every writable package — reaching 400+ distinct packages and 1,700+ versions.
- Malicious keyv@6.0.0 published at 09:35 UTC; ten more packages (cacheable, cacheable-request, cache-manager, flat-cache, file-entry-cache, @cacheable/*, ecto) published with malicious payloads over the following ~53 minutes.
- Attacker begins compromising the keyv/cacheable maintainer identity at 09:00 UTC and introduces IDE persistence payloads (VS Code + Claude hooks) via commits ee2681a9 and d8c850c7 under the github-actions[bot] identity.
- Shoulder.dev flags keyv@5.5.2, 5.5.3, 5.5.5, 5.6.0 as high-risk install-time payload: reads env credentials, contacts remote host, ships obfuscated second stage — reveals earlier infiltration than initially suspected
- npm registry deprecates identified malicious package versions (keyv@6.0.0, etc.) — versions remain downloadable for existing lock files but flagged as compromised
- Wiz Research (Merav Bar) publishes detailed technical analysis disclosing the attack — identifies Shai-Hulud lineage, ETH RPC C2 evolution, full IOC set, and affected packages; npm registry begins deprecating malicious versions
- Stable malicious version keyv@6.0.0 published to npm registry, alongside cacheable-request@13.0.20, cache-manager@7.2.10, @cacheable/utils@2.5.1, and malicious versions across @ornikar/* (27 packages), @qlik/* (4 packages), picasso-plugin-*, and other packages — total 868 packages, 1,381 versions across the keyv/cacheable dependency ecosystem
- Research finalized: ~1,300 GitHub repositories carry the 'Shai-Hulud: Here We Go Again' exfiltration description; campaign remains active with no CVE or GHSA assigned.
Update history for TL-2026-1861
- 2026-10-04 — keyv and cacheable npm Packages Hijacked in Worm-Like Supply Chain Attack (Mini Shai-Hulud descendant, "ChainDrop"): What changed No field escalation: severity CRITICAL, exploitability ACTIVE and status ACTIVE are already at maximum. New indicators (7) 1 new SHA-256 (community setup.mjs variant), the .claude/settings.json and .vscode/tasks.json persistenc
- 2026-08-05 — keyv/cacheable npm Ecosystem Hijacked — Mini Shai-Hulud Worm Supply Chain Attack (400+ Packages): What changed No field escalation — severity_level (CRITICAL), exploitability (ACTIVE), and status (ACTIVE) are already at maximum in the existing record. The newer report substantially expands the technical picture: worm self-propagation vi
Sources cited for Keyv and Cacheable npm Supply Chain Attack via Compromised
- Keyv and cacheable npm Package Hijacked in Supply Chain Attack
- Shoulder.dev — keyv@5.6.0 Threat Briefing
- Shoulder.dev — keyv@5.5.3 Threat Briefing
- Shai-Hulud: Here We Go Again (JFrog Research)
- Mini Shai-Hulud Research Note (Cloud Security Alliance)
- TanStack npm Packages Hit by Mini Shai-Hulud (Snyk)
- Breakingcircuitsllc/teampcp_shai_hulud.yar (YARA Rules)
- SigmaHQ — Shai-Hulud Proc Creation Detection (Windows)
- SigmaHQ — Shai-Hulud Proc Creation Detection (Linux)
Detection coverage for TL-2026-1861
As of 2026-10-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1861 across Splunk SPL, Microsoft KQL and Sigma, covering 62 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.