# Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware)

> Attackers compromised the GitHub maintainer account of Jared Wray (keyv/cacheable ecosystem) and published malicious versions across at least 868 npm packages (1,381 versions, over 2 billion combined monthly installs) carrying a Shai-Hulud-family payload that steals cloud credentials, infrastructure secrets, developer credentials, AI configurations, cryptocurrency wallets, and CI/CD pipeline secrets, using Ethereum RPC endpoints for C2 communications.

- **Published:** 2026-08-04T00:00:00Z
- **Last reviewed:** 2026-10-04T02:05:52.499Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1861
- **ID:** TL-2026-1861
- **Severity:** CRITICAL
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Actor:** TeamPCP
- **Detections:** 9 · **IOCs:** 62 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On August 4, 2026, Wiz Research disclosed an ongoing supply chain attack targeting the npm ecosystem through the compromise of Jared Wray's GitHub maintainer account, which governed the highly popular keyv and cacheable package families. The attacker published malicious versions (keyv@6.0.0, cacheable-request@13.0.20, cache-manager@7.2.10, @cacheable/utils@2.5.1, and dozens more across @ornikar/*, @qlik/*, picasso-plugin-*, and other packages) containing an identical obfuscated payload delivered via install-time hooks. The payload is a descendant of the Shai-Hulud malware family and shares code-level similarities with the prior TeamPCP and antv supply chain campaigns, but introduces a novel C2 mechanism: Ethereum JSON-RPC infrastructure (NodeReal, GetBlock, LlamaRPC) as a communication channel, representing a significant evolution in the malware's operational security posture. On execution, the payload enumerates the host environment (identifying build runners, cloud platforms, and CI/CD context), harvests credentials from cloud metadata services (~/.aws, ~/.gcp, ~/.azure), environment variables, configuration files, developer SSH keys, GitHub tokens, Kubernetes configurations, Terraform state, AI/ML framework configs (e.g. OpenAI API keys, Hugging Face tokens), and cryptocurrency wallet files. Exfiltrated data is transmitted to npm-cache[.]com (Cloudflare-hosted), while Ethereum RPC endpoints serve as C2 relay infrastructure. A distinctive attribution string — 'IfYouBlockThisAPIKeyItWillCrashTheLiveProductionServersOfAllThirdPartyClients' — was embedded in the payload. The malicious versions lacked build provenance. The npm registry subsequently deprecated the identified malicious versions. Wiz Research's investigation remains active, with newly identified packages being added as analysis continues. The attack's scale — affecting 868 packages spanning 1,381 versions with over 2 billion monthly npm installs across the dependency graph — ranks among the largest supply chain compromises of the npm ecosystem to date.

## MITRE ATT&CK

- T1078 Valid Accounts
- T1195 Supply Chain Compromise
- T1587 Develop Capabilities
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1027 Obfuscated Files or Information
- T1036 Masquerading
- T1552 Unsecured Credentials
- T1555 Credentials from Password Stores
- T1082 System Information Discovery
- T1087 Account Discovery
- T1580 Cloud Infrastructure Discovery
- T1071 Application Layer Protocol
- T1090 Proxy
- T1567 Exfiltration Over Web Service
- T1485 Data Destruction
- T1199 Trusted Relationship
- T1203 Exploitation for Client Execution
- T1105 Ingress Tool Transfer
- T1547 Boot or Logon Autostart Execution
- T1554 Compromise Host Software Binary
- T1546 Event Triggered Execution
- T1070 Indicator Removal
- T1528 Steal Application Access Token
- T1606 Forge Web Credentials
- T1560 Archive Collected Data
- T1568 Dynamic Resolution
- T1573 Encrypted Channel
- T1008 Fallback Channels
- T1496 Resource Hijacking
- T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
- T1059.007 Command and Scripting Interpreter
- T1070.004 Indicator Removal
- T1552.001 Unsecured Credentials
- T1552.005 Unsecured Credentials
- T1003.007 OS Credential Dumping
- T1005 Data from Local System
- T1119 Automated Collection
- T1102.001 Web Service
- T1071.001 Application Layer Protocol

## Sources

- [Keyv and cacheable npm Package Hijacked in Supply Chain Attack](https://www.wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack)
- [Shoulder.dev — keyv@5.6.0 Threat Briefing](https://shoulder.dev/npm/keyv/5.6.0)
- [Shoulder.dev — keyv@5.5.3 Threat Briefing](https://shoulder.dev/npm/keyv/5.5.3)
- [Shai-Hulud: Here We Go Again (JFrog Research)](https://research.jfrog.com/post/shai-hulud-here-we-go-again/)
- [Mini Shai-Hulud Research Note (Cloud Security Alliance)](https://labs.cloudsecurityalliance.org/research/csa-research-note-shai-hulud-ai-npm-supply-chain-attack-2026/)
- [TanStack npm Packages Hit by Mini Shai-Hulud (Snyk)](https://snyk.io/blog/tanstack-npm-packages-compromised/)
- [Breakingcircuitsllc/teampcp_shai_hulud.yar (YARA Rules)](https://github.com/Breakingcircuitsllc/teampcp_shai_hulud.yar)
- [SigmaHQ — Shai-Hulud Proc Creation Detection (Windows)](https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2025/Malware/Shai-Hulud/proc_creation_win_mal_shai_hulud_malicious_npm_package_installation.yml)
- [SigmaHQ — Shai-Hulud Proc Creation Detection (Linux)](https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2025/Malware/Shai-Hulud/proc_creation_lnx_mal_shai_hulud_malicious_npm_package_installation.yml)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1861
