Threat reportSupply ChainTL-2026-1861

Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware)

criticalACTIVE

Keyv and Cacheable npm Supply Chain Attack via Compromised (TL-2026-1861), also tracked as Keyv-Cacheable Supply Chain Compromise, is a critical-severity supply-chain compromise, first published 2026-08-04 and last reviewed 2026-10-04. It is attributed to TeamPCP with medium confidence, affects npm (Node Package Manager) keyv, maps to 42 MITRE ATT&CK techniques (T1003.007, T1005, T1008), and is covered by 9 detection rules and 62 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
42MITRE ATT&CK
Actors
1TeamPCP
Detection rules
9SPL · KQL · Sigma
IOCs
62Indicators of compromise

Key facts for TL-2026-1861

Threat ID
TL-2026-1861
Also known as
Keyv-Cacheable Supply Chain Compromise, Shai-Hulud Keyv Campaign, Jared Wray Maintainer Account Hijack
Severity
CRITICAL
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution
TeamPCP
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
technology, software-development, cloud-services, financial-services, artificial-intelligence, health
Target regions
North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
62
Updates
2026-10-04 · 2 updates · revalidated 2× · latest source

Malware and tooling in Keyv and Cacheable npm Supply Chain Attack via Compromised

Malware and tooling: Shai-Hulud, Ethereum JSON-RPC

How Keyv and Cacheable npm Supply Chain Attack via Compromised works

Attackers compromised the GitHub maintainer account of Jared Wray (keyv/cacheable ecosystem) and published malicious versions across at least 868 npm packages (1,381 versions, over 2 billion combined monthly installs) carrying a Shai-Hulud-family payload that steals cloud credentials, infrastructure secrets, developer credentials, AI configurations, cryptocurrency wallets, and CI/CD pipeline secrets, using Ethereum RPC endpoints for C2 communications.

On August 4, 2026, Wiz Research disclosed an ongoing supply chain attack targeting the npm ecosystem through the compromise of Jared Wray's GitHub maintainer account, which governed the highly popular keyv and cacheable package families. The attacker published malicious versions (keyv@6.0.0, cacheable-request@13.0.20, cache-manager@7.2.10, @cacheable/utils@2.5.1, and dozens more across @ornikar/*, @qlik/*, picasso-plugin-*, and other packages) containing an identical obfuscated payload delivered via install-time hooks. The payload is a descendant of the Shai-Hulud malware family and shares code-level similarities with the prior TeamPCP and antv supply chain campaigns, but introduces a novel C2 mechanism: Ethereum JSON-RPC infrastructure (NodeReal, GetBlock, LlamaRPC) as a communication channel, representing a significant evolution in the malware's operational security posture. On execution, the payload enumerates the host environment (identifying build runners, cloud platforms, and CI/CD context), harvests credentials from cloud metadata services (~/.aws, ~/.gcp, ~/.azure), environment variables, configuration files, developer SSH keys, GitHub tokens, Kubernetes configurations, Terraform state, AI/ML framework configs (e.g. OpenAI API keys, Hugging Face tokens), and cryptocurrency wallet files. Exfiltrated data is transmitted to npm-cache[.]com (Cloudflare-hosted), while Ethereum RPC endpoints serve as C2 relay infrastructure. A distinctive attribution string — 'IfYouBlockThisAPIKeyItWillCrashTheLiveProductionServersOfAllThirdPartyClients' — was embedded in the payload. The malicious versions lacked build provenance. The npm registry subsequently deprecated the identified malicious versions. Wiz Research's investigation remains active, with newly identified packages being added as analysis continues. The attack's scale — affecting 868 packages spanning 1,381 versions with over 2 billion monthly npm installs across the dependency graph — ranks among the largest supply chain compromises of the npm ecosystem to date.

MITRE ATT&CK techniques used in TL-2026-1861

Credential Access

T1003.007 OS Credential Dumping; T1528 Steal Application Access Token; T1552 Unsecured Credentials; T1552.001 Unsecured Credentials; T1552.005 Unsecured Credentials; T1555 Credentials from Password Stores; T1606 Forge Web Credentials

Collection

T1005 Data from Local System; T1119 Automated Collection; T1560 Archive Collected Data

Command and Control

T1008 Fallback Channels; T1071 Application Layer Protocol; T1071.001 Application Layer Protocol; T1090 Proxy; T1102.001 Web Service; T1568 Dynamic Resolution; T1573 Encrypted Channel

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1070.004 Indicator Removal

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service; T1567.001 Exfiltration Over Web Service

Execution

T1059 Command and Scripting Interpreter; T1059.007 Command and Scripting Interpreter; T1203 Exploitation for Client Execution; T1204 User Execution

Initial Access

T1078 Valid Accounts; T1195 Supply Chain Compromise; T1195.002 Supply Chain Compromise: Compromise Software Supply Chain; T1199 Trusted Relationship

Discovery

T1082 System Information Discovery; T1087 Account Discovery; T1580 Cloud Infrastructure Discovery

command-and-control

T1105 Ingress Tool Transfer

Impact

T1485 Data Destruction; T1496 Resource Hijacking

Persistence

T1546 Event Triggered Execution; T1547 Boot or Logon Autostart Execution; T1554 Compromise Host Software Binary

Resource Development

T1587 Develop Capabilities

Affected products and versions in Keyv and Cacheable npm Supply Chain Attack via Compromised

  • npm (Node Package Manager) — keyv
    Vulnerable versions: 5.5.2; 5.5.3; 5.5.5; 5.6.0; 6.0.0-alpha.1; 6.0.0-alpha.2; 6.0.0-rc.1; 6.0.0
    Fixed in: 6.0.0-beta.4+; 5.5.1 or earlier
  • npm (Node Package Manager) — cacheable-request
    Vulnerable versions: 13.0.20
    Fixed in: 13.0.19 or earlier
  • npm (Node Package Manager) — cache-manager
    Vulnerable versions: 7.2.10
    Fixed in: 7.2.9 or earlier
  • npm (Node Package Manager) — @cacheable/utils
    Vulnerable versions: 2.5.1
    Fixed in: 2.5.0 or earlier
  • npm (Node Package Manager) — @ornikar/* (27 packages)
    Vulnerable versions: Multiple versions (babel presets, eslint configs, repo configs, etc.)
    Fixed in: Pre-August 2026 versions
  • npm (Node Package Manager) — @qlik/* (4 packages)
    Vulnerable versions: @qlik/embed-react@2.5.3; @qlik/embed-runtime@1.6.4; @qlik/embed-web-components@1.7.3; @qlik/runtime-module-loader@1.5.1
    Fixed in: Pre-August 2026 versions
  • npm (Node Package Manager) — picasso-plugin-*
    Vulnerable versions: picasso-plugin-hammer@2.11.6; picasso-plugin-q@2.11.6
    Fixed in: Pre-August 2026 versions
  • npm (Node Package Manager) — @nebula.js/nucleus
    Vulnerable versions: 0.5.1
    Fixed in: 0.5.0 or earlier
  • npm (Node Package Manager) — @hubsync/web-sdk-react
    Vulnerable versions: 6.3.7
    Fixed in: 6.3.6 or earlier

Remediation for Keyv and Cacheable npm Supply Chain Attack via Compromised

Patches

  • Pin keyv to versions <5.5.2 or >=6.0.0-beta.4 (verify integrity SHA)
  • Pin cacheable-request to versions <13.0.20 or >=14.0.0
  • Pin cache-manager to versions <7.2.10 or >=8.0.0
  • Use overrides/resolutions in package.json to force clean versions across transitive dependencies

Immediate actions

  • Identify and remove affected package versions (keyv@6.0.0, cacheable-request@13.0.20, cache-manager@7.2.10, @cacheable/utils@2.5.1, and all listed @ornikar/*, @qlik/* malicious versions) from dev, build, and CI/CD environments
  • Scan lock files (package-lock.json, yarn.lock, pnpm-lock.yaml) for all 1,381 malicious package versions across 868 packages
  • Check for presence of /tmp/bun-dl-* directories and node_modules/keyv/Math_Symbol.js on any system that ran npm install on affected versions
  • Rotate ALL exposed credentials: cloud provider API keys, GitHub tokens, SSH keys, Kubernetes configurations, Terraform state credentials, AI/ML API keys, and any stored secrets in affected environments
  • Block network traffic to npm-cache[.]com, eth-mainnet.nodereal[.]io, go.getblock[.]io, and eth.llamarpc[.]com at perimeter firewalls and EDR

Workarounds

  • Disable npm install scripts globally (npm config set ignore-scripts true) until package inventory is clean
  • Audit all third-party packages that transitively pull in keyv/cacheable ecosystem
  • Monitor for connections to ETH RPC endpoints from non-crypto application code — this is a strong indicator of compromise

Longer-term hardening

  • Treat any system that installed affected packages as potentially compromised — rebuild from clean artifacts
  • Enable dependency allowlisting and package integrity verification in CI/CD pipelines
  • Implement provenance-based trust (require npm packages to carry valid provenance attestations)
  • Use npm audit and Socket.dev/Shoulder.dev-style automated scanning for install-time behavioral analysis
  • Add network monitoring for unexpected ETH RPC traffic from build/CI/CD environments
  • Enable staged publishing and trusted publisher bindings with hardware-bound OIDC tokens to prevent single-account compromise from affecting the full package surface

Weaknesses (CWE) in Keyv and Cacheable npm Supply Chain Attack via Compromised

CWE-1104, CWE-1357, CWE-829, CWE-506, CWE-94, CWE-798

Timeline of Keyv and Cacheable npm Supply Chain Attack via Compromised

Showing the 20 most recent tracked events.

  • Mini Shai-Hulud (TeamPCP) compromises @tanstack/*, @antv/* via GitHub Actions cache poisoning + OIDC token extraction; 639 malicious versions across 323 packages published with valid SLSA provenance — first-ever malware with valid provenance attestation
  • TeamPCP open-sources the Shai-Hulud worm code on GitHub under an MIT license ('Shai-Hulud: Open Sourcing The Carnage'), making payload-lineage attribution of later campaigns unreliable.
  • @antv ecosystem compromised via the 'atool' npm account — 637 malicious versions across 317 packages published in 22 minutes.
  • C2 domain npm-cache[.]com (104.21.35.216) registered ahead of the campaign.
  • Prior Shai-Hulud-family wave 'Miasma' compromises 32+ @redhat-cloud-services packages using a compromised Red Hat employee GitHub account with valid SLSA provenance.
  • GitHub maintainer account of Jared Wray (keyv/cacheable ecosystem creator) compromised by threat actors — exact method and date of initial breach unknown; investigation ongoing
  • keyv@6.0.0-rc.1 published from compromised account; release candidate triggers initial scanning by security monitoring platforms
  • Socket verifies 2,251 poisoned versions across 452 packages; 546 public exfiltration repositories ('Shai-Hulud: Here We Go Again') created on the day.
  • The StringListStore Ethereum contract, initially configured with three domains (npm-cache.com, pypi-get.com, js-mirror.com), is updated to return only npm-cache.com.
  • ~09:39 UTC: payload copied across 19 @keyv/* workspace packages; worm then spreads to nine unrelated organizations, one every 2-7 minutes.
  • npm registry rolls back some malicious versions from 'latest' (flat-cache to 6.1.23, cacheable-request to 13.0.19, cache-manager to 7.2.9); Snyk publishes advisory SNYK-JS-KEYV-18515941 (exploit maturity 'Attacked').
  • Wiz reports additional compromised packages at 13:45 UTC, adds Ethereum smart-contract C2 analysis at 15:00 UTC, and confirms 400+ distinct infected packages at 15:25 UTC.
  • Worm self-propagates using stolen npm tokens with bypass_2fa=true and package-write permission, republishing malicious versions across every writable package — reaching 400+ distinct packages and 1,700+ versions.
  • Malicious keyv@6.0.0 published at 09:35 UTC; ten more packages (cacheable, cacheable-request, cache-manager, flat-cache, file-entry-cache, @cacheable/*, ecto) published with malicious payloads over the following ~53 minutes.
  • Attacker begins compromising the keyv/cacheable maintainer identity at 09:00 UTC and introduces IDE persistence payloads (VS Code + Claude hooks) via commits ee2681a9 and d8c850c7 under the github-actions[bot] identity.
  • Shoulder.dev flags keyv@5.5.2, 5.5.3, 5.5.5, 5.6.0 as high-risk install-time payload: reads env credentials, contacts remote host, ships obfuscated second stage — reveals earlier infiltration than initially suspected
  • npm registry deprecates identified malicious package versions (keyv@6.0.0, etc.) — versions remain downloadable for existing lock files but flagged as compromised
  • Wiz Research (Merav Bar) publishes detailed technical analysis disclosing the attack — identifies Shai-Hulud lineage, ETH RPC C2 evolution, full IOC set, and affected packages; npm registry begins deprecating malicious versions
  • Stable malicious version keyv@6.0.0 published to npm registry, alongside cacheable-request@13.0.20, cache-manager@7.2.10, @cacheable/utils@2.5.1, and malicious versions across @ornikar/* (27 packages), @qlik/* (4 packages), picasso-plugin-*, and other packages — total 868 packages, 1,381 versions across the keyv/cacheable dependency ecosystem
  • Research finalized: ~1,300 GitHub repositories carry the 'Shai-Hulud: Here We Go Again' exfiltration description; campaign remains active with no CVE or GHSA assigned.

Update history for TL-2026-1861

Sources cited for Keyv and Cacheable npm Supply Chain Attack via Compromised

Detection coverage for TL-2026-1861

As of 2026-10-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1861 across Splunk SPL, Microsoft KQL and Sigma, covering 62 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
62 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats