Skip to main content
LIVE TUE, 11 AUG, 2026 BENGALURU · 28°C EDITION № 103 · FREE · NO LOGIN
AI AI · 2 MIN READ

Keyv npm package compromised in active supply chain attack

On August 4, 2026, attackers compromised the GitHub account of the maintainer behind Keyv, a key-value storage library with approximately 127 million weekl…

On August 4, 2026, attackers compromised the GitHub account of the maintainer behind Keyv, a key-value storage library with approximately 127 million weekly npm downloads, injecting a credential-stealing worm across the entire package family. This attack also affected other widely-used caching utilities owned by the same maintainer, including cacheable, flat-cache, and file-entry-cache, which have monthly downloads of 29 million, 565 million, and 557 million respectively, according to aikido.dev.

The attackers gained access by pushing malicious files through the compromised GitHub account, enabling the worm to spread across the entire set of related npm packages. This active supply chain attack exploited the trust developers place in these libraries, which are dependencies in numerous projects. The breach was detected and reported by security researchers at aikido.dev, who detailed the scope and mechanics of the attack on their blog.

Supply chain attacks on npm packages have become an increasing concern in the software development community, as they can silently compromise thousands of projects downstream. The Keyv compromise is notable due to the scale of downloads and the critical role of caching utilities in application performance. Previous incidents have shown that such attacks can lead to widespread credential theft and data breaches, underscoring the importance of securing open-source dependencies.

The maintainer’s GitHub account remains under investigation, and npm has taken steps to remove the malicious versions of the affected packages. Developers using Keyv and related libraries are advised to audit their dependencies and update to clean versions. The incident highlights the need for enhanced security measures in open-source package management systems.

Editorial standards. Reported and edited at Startupniti's news desk from the sources listed in the right rail. Every fact traces to a citation. If something looks wrong, write to corrections.
▸ WIRE
Premium content free for first 12 months · sign up to unlock Razorpay subscriptions launch Jan 2027 — ₹199/mo or ₹999/yr Every story reads every Indian tech source so you don't have to Every article cited · trust the source, not just the byline India's startup desk, edited daily Founders · Funding · Policy · Tech — three crawls a day Premium content free for first 12 months · sign up to unlock Razorpay subscriptions launch Jan 2027 — ₹199/mo or ₹999/yr Every story reads every Indian tech source so you don't have to Every article cited · trust the source, not just the byline India's startup desk, edited daily Founders · Funding · Policy · Tech — three crawls a day