# Shai-Hulud NPM Worm Compromises keyv, file-entry-cache, flat-cache and Hundreds of Popular npm Packages via Maintainer Account Takeover

> On August 4, 2026, attackers compromised the GitHub account of Jared Wray, the maintainer of keyv (~127M weekly downloads), file-entry-cache (~557M monthly), and flat-cache (~565M monthly), injecting setup.mjs (Bun runtime dropper) and Math_Symbol.js (AES-256-GCM obfuscated credential stealer) with a preinstall hook across all @keyv/* sub-packages. The self-propagating Shai-Hulud worm has compromised at least 868 packages across 1,381 versions, with a combined estimated 2+ billion monthly installs, exfiltrating npm tokens, GitHub PATs, AWS keys, Vault tokens, SSH keys, crypto wallets, and CI/CD secrets via npm-cache[.]com C2 and GitHub dead-drop repositories.

- **Published:** 2026-08-04T00:00:00Z
- **Last reviewed:** 2026-08-04T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1863
- **ID:** TL-2026-1863
- **Severity:** CRITICAL
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Actor:** TeamPCP
- **Detections:** 9 · **IOCs:** 24 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On August 4, 2026 at approximately 09:00 UTC, attackers compromised the GitHub account of Jared Wray, the maintainer of the keyv key-value storage library (~127 million weekly downloads), along with the related cacheable, flat-cache, and file-entry-cache ecosystems. The attacker pushed malicious code directly to the main branch of each repository and immediately cut new releases, carrying valid SLSA v1 provenance signatures generated by GitHub Actions under the compromised account's identity.

Each affected package received three changes: (1) injection of setup.mjs, a heavily obfuscated dropper that silently downloads the Bun JavaScript runtime (v1.3.13) from GitHub and uses it to execute the payload; (2) injection of Math_Symbol.js, a ~728KB to multi-MB obfuscated payload encrypted with AES-256-GCM gzip compression and PBKDF2-SHA256 key derivation; and (3) a preinstall hook ("node setup.mjs") added to package.json, causing automatic execution on any npm install. The commit 174f6a5 on keyv's repository touched 19 packages across the @keyv/* monorepo (compression, core, encryption, serialization, and storage packages), stripping all legitimate package.json metadata to only a files array pointing at the malicious artifacts.

The payload is a descendant of the Shai-Hulud malware family (MITRE ATT&CK ID S9008), attributed to the TeamPCP threat actor (also tracked as PCPcat, DeadCatx3, ShellForce, CipherForce, Persy_PCP). First documented in September 2025, Shai-Hulud has evolved through at least four major campaigns: V1 (initial rxnt-authentication patient zero), V2/2.0 (796+ packages, November 2025), SANDWORM_MODE (typosquatting AI developer tools, February 2026), and "The Third Coming" (@bitwarden/cli compromise, April 2026). The August 4, 2026 keyv wave represents the largest single wave by package count and download volume.

The worm's credential harvesting spans a broad range of targets: npm registry tokens from .npmrc files; GitHub CLI tokens (classic PATs, session tokens, OIDC tokens); AWS access keys from ~/.aws/credentials, environment variables, IMDS/ECS metadata; HashiCorp Vault tokens from VAULT_TOKEN env var and HTTP fallback; SSH private keys; Kubernetes service account tokens and kubeconfig; AI/LLM API keys (Anthropic, OpenAI, Google, Groq, Together, Fireworks, Replicate, Mistral, Cohere); cryptocurrency wallet keystores (Bitcoin, Ethereum, Monero, Zcash); 1Password, Bitwarden unlocked vaults; and CI/CD runner process memory (including GitHub Actions OIDC tokens from ACTIONS_ID_TOKEN_REQUEST_URL). Exfiltration uses a four-level fallback architecture: primary HTTPS POST to git-tanstack.com:443/router or npm-cache[.]com, signed-commit C2 discovery via thebeautifulmarchoftime repository, attacker-controlled GitHub dead-drop repos with Dune-themed names (sardaukar-*, sandworm-*), and victim's own GitHub account via stolen ghp_/gho_ tokens. Data is encrypted with AES-256-GCM + RSA-OAEP before exfiltration.

Persistence mechanisms include preinstall/prepare lifecycle hooks, GitHub Actions workflow injection (dependabot/github_actions/format/setup-formatter branches with malicious codeql_analysis.yml impersonating github-advanced-security[bot]), .claude/settings.json and .vscode/tasks.json injection for AI toolchain hijack, systemd user services (gh-token-monitor.service) and macOS LaunchAgents as dead-man switches that execute rm -rf ~/ on token revocation, and git global hook templates via init.templateDir. The worm also deploys a gh-token-monitor that polls api.github.com/user every 60 seconds and triggers data destruction if the token is revoked. On CI/CD runners, it targets runner process memory with sudo python3 to extract all injected secrets including masked ones.

Wiz Research, Datadog Security Labs, HEAL Security, JFrog, Phoenix Security, Cloud Security Alliance, and Unit 42 have all published technical analyses. Datadog maintains a dynamically updated CSV of compromised packages. The npm ecosystem remains under active threat as the worm's source code was publicly released on GitHub on May 12, 2026, enabling copycat actors. No CVE has been assigned for this specific wave as of publication.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1546 Event Triggered Execution
- T1543 Create or Modify System Process
- T1548 Abuse Elevation Control Mechanism
- T1027 Obfuscated Files or Information
- T1036 Masquerading
- T1553 Subvert Trust Controls
- T1552 Unsecured Credentials
- T1555 Credentials from Password Stores
- T1528 Steal Application Access Token
- T1550 Use Alternate Authentication Material
- T1082 System Information Discovery
- T1119 Automated Collection
- T1213 Data from Information Repositories
- T1071 Application Layer Protocol
- T1567 Exfiltration Over Web Service
- T1677 Poisoned Pipeline Execution
- T1098 Account Manipulation
- T1485 Data Destruction

## Sources

- [Datadog Security Labs: NPM Worm Compromises Popular NPM Packages](https://securitylabs.datadoghq.com/articles/npm-worm-compromises-popular-npm-packages/)
- [Wiz Research: keyv and cacheable npm Package Hijacked in Supply Chain Attack](https://www.wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack)
- [HEAL Security: keyv npm package with 127M weekly downloads compromised in Shai-Hulud attack](https://healsecurity.com/keyv-npm-package-with-127m-weekly-downloads-compromised-in-shai-hulud-attack/)
- [Malicious commit 174f6a5 on keyv - setup.mjs and Math_Symbol.js injection across @keyv/*](https://github.com/jaredwray/keyv/commit/174f6a55690b0812a69adef47260ba8714a9be48)
- [Datadog Indicators of Compromise - keyv-campaign malicious packages CSV](https://github.com/DataDog/indicators-of-compromise/blob/keyv-campaign/keyv-campaign/malicious-packages.csv)
- [JFrog Research: Shai-Hulud: Here We Go Again](https://research.jfrog.com/post/shai-hulud-here-we-go-again/)
- [MITRE ATT&CK: Shai-Hulud (S9008)](https://attack.mitre.org/software/S9008/)
- [Cloud Security Alliance: CSA Research Note - Shai-Hulud npm Worm AI Developer Supply Chain](https://labs.cloudsecurityalliance.org/research/csa-research-note-shai-hulud-npm-worm-ai-developer-supply-ch/)
- [Phoenix Security: Sha1-Hulud Worm Analysis - Persistence, IOCs](https://phoenix.security/sha1-hulud-shai-hulud-worm-analysis-persistence-iocs/)
- [Unit 42: Monitoring npm Supply Chain Attacks (Shai-Hulud CI/CD Analysis)](https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/)
- [Socket Research: Shai Hulud Strikes Again - SANDWORM_MODE Campaign](https://socket.dev/blog/shai-hulud-strikes-again)
- [Snyk: TanStack npm Packages Compromised (CVE-2026-45321)](https://snyk.io/blog/tanstack-npm-packages-compromised/)
- [Wiz Research IOC List - keyv-packages.csv](https://github.com/wiz-sec-public/wiz-research-iocs/blob/main/reports/keyv-packages.csv)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1863
