Keyv & Cacheable NPM Packages in Ongoing Supply Chain Attack

Executive Summary

On August 4th, 2026, a supply chain attack was identified on two npm packages, Keyv and Cacheable by Wiz Research. Keyv and Cacheable are very popular JavaScript libraries with over 150 million weekly downloads and are used in many JavaScript deployments. Multiple malicious packages within the Keyv/Cacheable system were published via a compromised GitHub maintainer account to deploy a variant of the Shai-Hulud malware family.

The malware collects a broad range of credentials used to publish future npm packages within a continuous integration / continuous deployment (CI/CD) pipeline, including personal and production credentials to facilitate further propagation. These secrets were exfiltrated using the description “Shai_Hulud: Here We Go Again” with the commit message “IfYouBlockThisAPIKeyItWillCrashTheLiveProductionServersOfAllThirdPartyClients”.

Organizations that are affected should immediately audit their environments to confirm whether any identified npm packages were installed. If so, treat the machine as compromised and follow the Mitigations and Workarounds section below.

Affected Systems and Products

 Product  Fixed Version

 babel-plugin-linaria-css-to-undefined

 0.3.1

 @cacheable/utils

 2.5.1

 cache-manager

 7.2.10

 cacheable-request

 13.0.20

 http-metrics-middleware

 2.2.2

 @hubsync/web-sdk-react

 6.3.7

 keyv

 6.0.0

 @nebula.js/nucleus

 0.5.1

 @ornikar/babel-preset-base

 6.0.3

 @ornikar/babel-preset-kitt-universal

 8.0.3

 @ornikar/babel-preset-react

 6.1.4

 @ornikar/browserslist-config

 8.0.3

 @ornikar/commitlint-config

 8.3.2

 @ornikar/eslint-config-babel

 24.0.1

 @ornikar/eslint-config-react

 24.0.1

 @ornikar/eslint-config-typescript

 24.0.1

 @ornikar/eslint-config-typescript-react

 24.0.1

 @ornikar/eslint-plugin-neverthrow

 1.3.1

 @ornikar/eslint-plugin-ornikar

 24.0.1

 @ornikar/graphql-config

 1.1.1

 @ornikar/intl-config

 10.0.2

 @ornikar/kitt2

 1.0.1

 @ornikar/monorepo-config

 14.3.2

 @ornikar/postcss-config

 9.1.2

 @ornikar/prettier-config

 9.0.3

 @ornikar/prismic-components

 0.0.2

 @ornikar/react-modern-calendar-datepicker

 3.2.1

 @ornikar/react-native-svg-transformer

 1.0.6

 @ornikar/renovate-config

 9.0.2

 @ornikar/repo-config-react

 13.0.8

 @ornikar/repo-config-react-legacy-css

 15.1.2

 @ornikar/rollup-plugin-postcss

 2.0.5

 @ornikar/stylelint-config

 14.0.3

 @ornikar/typed-css-modules-loader

 0.8.2

 picasso-plugin-hammer

 2.11.6

 picasso-plugin-q

 2.11.6

 pob-test-package-in-monorepo

 5.2.1

 @qlik/embed-react

 2.5.3

 @qlik/embed-runtime

 1.6.4

 @qlik/embed-web-components

 1.7.3

 @qlik/runtime-module-loader

 1.5.1

 @thiennq/docs-viewer

 1.6.2

Mitigations and Workarounds

Affected organizations should block the following command-and-control endpoints identified used for this attack:

  • npm-cache[.]com - 104.21.35[.]216
  • eth-mainnet.nodereal[.]io - 35.175.164[.]77
  • go.getblock[.]io - 185.44.207[.]215
  • eth.llamarpc[.]com - 172.67.167[.]200
  • pypi-get[.]com - 172.67.136[.]8, 104[.]21.54.63
  • js-mirror[.]com - 104.21.88[.]80, 172.67.174[.]77

If you believe that a machine has already been compromised, we do not advise cleaning in place and instead recommend reimaging or rebuilding affected machines from known good images.

Using pinned versions of libraries is also recommended to prevent this kind of attack if new malicious versions are released for any library.

Additionally, npm offers a npm config set min-release-age 3 configuration setting that will enforce a 48 to 72-hour delay on new package releases before installing them on your machine. This is advised for all developers using external packages. For machines running without human interaction, such as CI/CD pipelines, we advise not only pinning package versions but also disabling scripts on installation with the --ignore-scripts argument wherever possible.

Patches

While not strictly a patch, affected npm packages should be removed and purged from impacted machines. This involves removing the affected packages and installing pinned versions of the unaffected npm package with these commands:

  • rm -rf node_modules/plain-crypto-js
  • npm install --ignore-scripts
  • npm cache clean --force

Indicators of Compromise

Network Activity

The following domains and IP addresses have been associated with malicious activity observed during this campaign.

 Domain  IP Address

 npm-cache[.]com

 104.21.35[.]216

 eth-mainnet.nodereal[.]io

 35.175.164[.]77

 go.getblock[.]io

 185.44.207[.]215

 eth.llamarpc[.]com

 172.67.167[.]200

 pypi-get[.]com

 172.67.136[.]8, 104.21.54[.]63

 js-mirror[.]com

 104.21.88[.]80, 172.67.174[.]77

Wiz Research has also identified the user-agent performing malicious calls as Bun/1.3.13

Files

The following file names and hashes have been identified as part of the malware’s execution.

 Name  SHA1 Hash

 Math_Symbol.js

 35a672cf34b996b91f3e1c28cbf3a05a37e036e4

 math_init.js

 35a672cf34b996b91f3e1c28cbf3a05a37e036e4

 setup.mjs (in .claude)

 686aa40d0fc22c8d569494543a0f891f359f2f99

 setup.mjs (in .vscode)

 f525d52ceb966516686b482d3dc0137028cc6a63

How Beazley Security is Responding

Beazley Security is conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients.

If you believe your organization may have been impacted by this attack campaign and need support, please contact our Incident Response team.

Sources

Vous êtes au courant d'un incident qui a un impact sur votre secteur d'activité ? Faites-nous savoir :

Report an incident