Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)
A sophisticated supply-chain attack leveraging compromised npm packages (keyv and cacheable) has been active since August 4th, 2026. Attackers exploited a vulnerability to inject malicious code into widely used libraries, stealing credentials and establishing persistent execution on compromised hosts. The attack is notable for its ability to execute without requiring users to install anything, and for using a 'dead-man's switch' that turns remediation efforts into the trigger for malicious activity. The campaign is characterized by a worm-like propagation, with attackers re-publishing trojanized versions of packages using stolen npm tokens.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data