← Radar

Incident case file

Sign in to watch

npm Supply Chain Attack — Shai-Hulud Wave 6 (Keyv/Cacheable Ecosystem)

Incident date 2026-08-03Last updated Aug 14, 2026

1 views

ContainednpmGitHub supply chain; Ethereum used for C2 resolutionSupply chain attackCluster: KEYV-SUPPLY-2026-08

Estimated loss

$0

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

70%

Facts and investigation

Ledger

Attacker

MISSING — attacker identity not publicly disclosed. Initial access was gained by compromising the GitHub account of package maintainer 'jaredwray.'

Funds moved to

No direct cryptocurrency theft has been publicly quantified for this incident. The malicious payload's primary objective was credential harvesting (npm, GitHub, AWS, GCP, Azure, Kubernetes, HashiCorp Vault, and SSH tokens) rather than direct fund extraction, though any crypto wallet files present on infected development machines were potentially exposed. Command-and-control resolution used Ethereum smart contract 0xE1f2395ee43e45A1556EC6438a88c31B83493103 (a StringListStore-type contract, not an

Linked

Affected packages include keyv@6.0.0 and a broader set of at least 868 packages / 1,381 versions across the dependency ecosystem (including flat-cache, file-entry-cache, cacheable-request, cacheable, cache-manager, and other related packages), per independent analysis. Combined exposure across the affected package tree was estimated at more than two billion monthly npm installs. Independent researchers counted several hundred public GitHub repositories bearing exfiltration signatures created on

Chronology

1 beat
  1. August 4, 2026 (approximately 09:00 UTC): An attacker compromises the GitHub account belonging to package maintainer 'jaredwray' and pushes malicious changes to the keyv repository, achieving valid cryptographic provenance through the repository's own GitHub Actions release automation pipeline. Approximately 09:35 UTC: A trojanized version of the keyv@6.0.0 package is published to the npm registry. The package contains a preinstall script hook that downloads and executes the Bun JavaScript runtime, which in turn runs an obfuscated second-stage payload on any machine where the package is installed. The payload is designed to harvest credentials for npm, GitHub, AWS, GCP, Azure, Kubernetes, HashiCorp Vault, and SSH access, as well as any locally accessible cryptocurrency wallet files, and additionally installs persistence hooks specifically targeting configuration directories used by AI coding assistants and popular IDEs. Command-and-control resolution for the malware occurs via an on-chain lookup against Ethereum smart contract 0xE1f2395ee43e45A1556EC6438a88c31B83493103, which resolves to the domain npm-cache[.]com. Over the following hours, the malware self-propagates in worm-like fashion by using freshly harvested npm publishing credentials from each newly infected maintainer account to compromise and republish malicious versions of hundreds of additional downstream and sibling packages throughout the Keyv/Cacheable dependency tree, rapidly expanding combined exposure to an estimated two billion-plus monthly package installs across at least 868 distinct packages and 1,381 versions. Independent security researchers document several hundred distinct public GitHub repositories bearing consistent exfiltration signatures created on August 4 alone, indicating highly automated, large-scale attacker infrastructure. August 5, 2026 (approximately 03:37 UTC): SlowMist_Team publishes a formal threat-intelligence alert flagging the large-scale npm supply chain compromise to the broader security community. Over the following 24-48 hours, independent security research teams publish detailed technical analyses of the attack's mechanics and indicators of compromise, and coordinate directly with npm and GitHub platform operators to identify, remove, or roll back malicious package versions across the affected ecosystem. As of the reporting window's close, no direct cryptocurrency theft amount has been publicly quantified for this incident — the attack's apparent primary objective was broad-spectrum credential harvesting and supply-chain persistence rather than immediate, direct fund extraction, though any cryptocurrency wallets accessible on compromised development machines were potentially at risk. Standard remediation guidance for potentially affected organizations includes full rotation of all npm, GitHub, and cloud-provider credentials, plus careful auditing of project lockfiles to confirm complete removal of any compromised package versions.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)