Threat reportSupply ChainTL-2026-1863
Shai-Hulud NPM Worm Compromises keyv, file-entry-cache, flat-cache and Hundreds of Popular npm Packages via Maintainer Account Takeover
Shai-Hulud NPM Worm Compromises keyv, file-entry-cache (TL-2026-1863), also tracked as Shai-Hulud, is a critical-severity supply-chain compromise, first published 2026-08-04. It is attributed to TeamPCP with medium confidence, affects npm keyv, maps to 21 MITRE ATT&CK techniques (T1027, T1036, T1059), and is covered by 9 detection rules and 24 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 21MITRE ATT&CK
- Actors
- 1TeamPCP
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 24Indicators of compromise
Key facts for TL-2026-1863
- Threat ID
- TL-2026-1863
- Also known as
- Shai-Hulud, Sha1-Hulud, Mini Shai-Hulud, CanisterWorm, team PCP Campaign, keyv Worm
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- TeamPCP
- Attribution confidence
- MEDIUM
- Motivation
- ESPIONAGE
- Target sectors
- software, technology, finance, health, government administration, ecommerce
- Target regions
- North America, Europe, Asia-Pacific, Global
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in Shai-Hulud NPM Worm Compromises keyv, file-entry-cache
Malware and tooling: Shai-Hulud, Session/Oxen P2P Network, gh-token-monitor
How Shai-Hulud NPM Worm Compromises keyv, file-entry-cache works
On August 4, 2026, attackers compromised the GitHub account of Jared Wray, the maintainer of keyv (~127M weekly downloads), file-entry-cache (~557M monthly), and flat-cache (~565M monthly), injecting setup.mjs (Bun runtime dropper) and Math_Symbol.js (AES-256-GCM obfuscated credential stealer) with a preinstall hook across all @keyv/* sub-packages. The self-propagating Shai-Hulud worm has compromised at least 868 packages across 1,381 versions, with a combined estimated 2+ billion monthly installs, exfiltrating npm tokens, GitHub PATs, AWS keys, Vault tokens, SSH keys, crypto wallets, and CI/CD secrets via npm-cache[.]com C2 and GitHub dead-drop repositories.
On August 4, 2026 at approximately 09:00 UTC, attackers compromised the GitHub account of Jared Wray, the maintainer of the keyv key-value storage library (~127 million weekly downloads), along with the related cacheable, flat-cache, and file-entry-cache ecosystems. The attacker pushed malicious code directly to the main branch of each repository and immediately cut new releases, carrying valid SLSA v1 provenance signatures generated by GitHub Actions under the compromised account's identity.
Each affected package received three changes: (1) injection of setup.mjs, a heavily obfuscated dropper that silently downloads the Bun JavaScript runtime (v1.3.13) from GitHub and uses it to execute the payload; (2) injection of Math_Symbol.js, a ~728KB to multi-MB obfuscated payload encrypted with AES-256-GCM gzip compression and PBKDF2-SHA256 key derivation; and (3) a preinstall hook ("node setup.mjs") added to package.json, causing automatic execution on any npm install. The commit 174f6a5 on keyv's repository touched 19 packages across the @keyv/* monorepo (compression, core, encryption, serialization, and storage packages), stripping all legitimate package.json metadata to only a files array pointing at the malicious artifacts.
The payload is a descendant of the Shai-Hulud malware family (MITRE ATT&CK ID S9008), attributed to the TeamPCP threat actor (also tracked as PCPcat, DeadCatx3, ShellForce, CipherForce, Persy_PCP). First documented in September 2025, Shai-Hulud has evolved through at least four major campaigns: V1 (initial rxnt-authentication patient zero), V2/2.0 (796+ packages, November 2025), SANDWORM_MODE (typosquatting AI developer tools, February 2026), and "The Third Coming" (@bitwarden/cli compromise, April 2026). The August 4, 2026 keyv wave represents the largest single wave by package count and download volume.
The worm's credential harvesting spans a broad range of targets: npm registry tokens from .npmrc files; GitHub CLI tokens (classic PATs, session tokens, OIDC tokens); AWS access keys from ~/.aws/credentials, environment variables, IMDS/ECS metadata; HashiCorp Vault tokens from VAULT_TOKEN env var and HTTP fallback; SSH private keys; Kubernetes service account tokens and kubeconfig; AI/LLM API keys (Anthropic, OpenAI, Google, Groq, Together, Fireworks, Replicate, Mistral, Cohere); cryptocurrency wallet keystores (Bitcoin, Ethereum, Monero, Zcash); 1Password, Bitwarden unlocked vaults; and CI/CD runner process memory (including GitHub Actions OIDC tokens from ACTIONS_ID_TOKEN_REQUEST_URL). Exfiltration uses a four-level fallback architecture: primary HTTPS POST to git-tanstack.com:443/router or npm-cache[.]com, signed-commit C2 discovery via thebeautifulmarchoftime repository, attacker-controlled GitHub dead-drop repos with Dune-themed names (sardaukar-*, sandworm-*), and victim's own GitHub account via stolen ghp_/gho_ tokens. Data is encrypted with AES-256-GCM + RSA-OAEP before exfiltration.
Persistence mechanisms include preinstall/prepare lifecycle hooks, GitHub Actions workflow injection (dependabot/github_actions/format/setup-formatter branches with malicious codeql_analysis.yml impersonating github-advanced-security[bot]), .claude/settings.json and .vscode/tasks.json injection for AI toolchain hijack, systemd user services (gh-token-monitor.service) and macOS LaunchAgents as dead-man switches that execute rm -rf ~/ on token revocation, and git global hook templates via init.templateDir. The worm also deploys a gh-token-monitor that polls api.github.com/user every 60 seconds and triggers data destruction if the token is revoked. On CI/CD runners, it targets runner process memory with sudo python3 to extract all injected secrets including masked ones.
Wiz Research, Datadog Security Labs, HEAL Security, JFrog, Phoenix Security, Cloud Security Alliance, and Unit 42 have all published technical analyses. Datadog maintains a dynamically updated CSV of compromised packages. The npm ecosystem remains under active threat as the worm's source code was publicly released on GitHub on May 12, 2026, enabling copycat actors. No CVE has been assigned for this specific wave as of publication.
MITRE ATT&CK techniques used in TL-2026-1863
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol
Initial Access
T1078 Valid Accounts; T1195 Supply Chain Compromise
Discovery
T1082 System Information Discovery
persistence
Collection
T1119 Automated Collection; T1213 Data from Information Repositories
Impact
Credential Access
T1528 Steal Application Access Token; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Persistence
T1543 Create or Modify System Process
privilege-escalation
T1546 Event Triggered Execution
Privilege Escalation
T1548 Abuse Elevation Control Mechanism
lateral-movement
T1550 Use Alternate Authentication Material
defense-impairment
Exfiltration
T1567 Exfiltration Over Web Service
execution
Affected products and versions in Shai-Hulud NPM Worm Compromises keyv, file-entry-cache
- npm — keyv
Vulnerable versions: 6.0.0 - npm — flat-cache
Vulnerable versions: 6.1.24 - npm — file-entry-cache
Vulnerable versions: 11.1.6 - npm — cacheable-request
Vulnerable versions: 13.0.20 - npm — cache-manager
Vulnerable versions: 7.2.10 - npm — @cacheable/utils
Vulnerable versions: 2.5.1 - npm — @cacheable/memory
Vulnerable versions: 2.2.1 - npm — @cacheable/node-cache
Vulnerable versions: 3.1.2 - npm — @cacheable/net
Vulnerable versions: 2.1.1 - npm — cacheable
Vulnerable versions: 2.5.1
Remediation for Shai-Hulud NPM Worm Compromises keyv, file-entry-cache
Immediate actions
- Pin npm lifecycle scripts: set ignore-scripts=true in .npmrc across all developer workstations and CI/CD runners
- Rotate ALL exposed credentials NOW - npm tokens, GitHub PATs, AWS keys, Vault tokens, SSH keys, cloud service accounts - do not proceed sequentially
- Stop and disable gh-token-monitor.service (Linux systemd) before any token revocation to prevent dead-man-switch data destruction
- Remove malicious package versions from lockfiles (keyv 6.0.0, flat-cache 6.1.24, file-entry-cache 11.1.6, cacheable-request 13.0.20, cache-manager 7.2.10, @cacheable/utils 2.5.1, and all packages from the Datadog IOC CSV)
- Block C2 infrastructure at network perimeter: npm-cache.com, git-tanstack.com, audit.checkmarx.cx, 83.142.209.194, eth-mainnet.nodereal.io, go.getblock.io, eth.llamarpc.com
- Rebuild all CI/CD runners, Docker images, and developer workstations from clean OS images
Workarounds
- Temporarily set ignore-scripts=true globally until all affected versions are identified and removed
- Block direct npm/pip install from CI runners; route through internal proxy with package allowlisting
- Disable pull_request_target trigger in open-source repositories accepting external contributions
- Audit all GitHub Actions workflows for unauthorized modifications referencing codeql_analysis.yml or ci-quality/code-quality-check
Longer-term hardening
- Adopt npm OIDC-based provenance attestation with short-lived tokens and strict audience constraints
- Implement runtime behavioral monitoring of preinstall/postinstall lifecycle hooks in CI/CD
- Deploy dependency allowlists with integrity verification (lockfile pinning, hash-locked packages)
- Isolate credential vaults from developer workstations; enforce per-session credential injection
- Treat MCP server configurations with the same scrutiny as browser extensions; never allow credential access per tool invocation
Weaknesses (CWE) in Shai-Hulud NPM Worm Compromises keyv, file-entry-cache
Timeline of Shai-Hulud NPM Worm Compromises keyv, file-entry-cache
- Shai-Hulud patient zero identified: rxnt-authentication version 0.0.3 published to npm. First documented self-replicating supply chain worm in the npm ecosystem. Discovered by ReversingLabs researchers.
- Shai-Hulud 2.0 campaign compromises 796 unique npm packages across 1,092 versions, reaching 20M+ weekly downloads. @ctrl/tinycolor (2.2M weekly downloads), ngx-bootstrap (~300K), and ng2-file-upload (~100K) among high-profile casualties. Introduces self-directed lateral movement via public GitHub repo credential harvesting.
- SANDWORM_MODE campaign disclosed by Socket Research Team. 19 malicious typosquatted packages impersonating Claude Code (claud-code, cloude) and OpenClaw. Introduces three-channel cascade exfiltration including DNS tunneling, CI time-gate detection, and weaponized GitHub Actions that serialize pipeline secrets.
- "The Third Coming" campaign: official @bitwarden/cli version 2026.4.0 compromised via malicious preinstall hook that bootstraps Bun runtime and deploys ~10MB obfuscated payload. AES-256-GCM encrypted exfiltration to public GitHub repos with Dune-themed repository names. Targets ~/.claude.json and ~/.claude/mcp.json.
- Mini Shai-Hulud / TeamPCP wave hits TanStack: 84 malicious versions across 42 @tanstack/* packages published via CI cache poisoning with valid Sigstore provenance signatures. First documented case of malicious npm package with valid SLSA provenance. Tracked as CVE-2026-45321.
- Shai-Hulud worm source code publicly released on GitHub, enabling widespread copycat and derivative attacks across the software supply chain.
- ~13:20 CEST: At least 868 packages across 1,381 versions confirmed compromised. Combined estimated 2+ billion monthly npm installs affected. Wiz confirms the payload as a Shai-Hulud descendant related to TeamPCP and antv campaigns.
- Wiz Research and Datadog Security Labs detect the ongoing attack and publish initial findings. Datadog publishes a living CSV of compromised packages on GitHub.
- Simultaneous malicious releases published to npm: keyv 6.0.0, flat-cache 6.1.24, file-entry-cache 11.1.6, cacheable-request 13.0.20, cache-manager 7.2.10, @cacheable/utils 2.5.1, and others. All carry valid SLSA v1 provenance from GitHub Actions under the compromised identity.
- Commit 174f6a5 pushed to keyv repository: setup.mjs and Math_Symbol.js injected into all @keyv/* sub-packages (19 packages across compression, core, encryption, serialization, and storage categories). All legitimate package.json metadata stripped to only the files array.
- ~09:00 UTC: GitHub account of Jared Wray (maintainer of keyv, flat-cache, file-entry-cache, cacheable) compromised. Attacker pushes malicious code to main branches of all repositories.
Sources cited for Shai-Hulud NPM Worm Compromises keyv, file-entry-cache
- Datadog Security Labs: NPM Worm Compromises Popular NPM Packages
- Wiz Research: keyv and cacheable npm Package Hijacked in Supply Chain Attack
- HEAL Security: keyv npm package with 127M weekly downloads compromised in Shai-Hulud attack
- Malicious commit 174f6a5 on keyv - setup.mjs and Math_Symbol.js injection across @keyv/*
- Datadog Indicators of Compromise - keyv-campaign malicious packages CSV
- JFrog Research: Shai-Hulud: Here We Go Again
- MITRE ATT&CK: Shai-Hulud (S9008)
- Cloud Security Alliance: CSA Research Note - Shai-Hulud npm Worm AI Developer Supply Chain
- Phoenix Security: Sha1-Hulud Worm Analysis - Persistence, IOCs
- Unit 42: Monitoring npm Supply Chain Attacks (Shai-Hulud CI/CD Analysis)
- Socket Research: Shai Hulud Strikes Again - SANDWORM_MODE Campaign
- Snyk: TanStack npm Packages Compromised (CVE-2026-45321)
- Wiz Research IOC List - keyv-packages.csv
Detection coverage for TL-2026-1863
As of 2026-08-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1863 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1863
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.