npm supply-ch2026-08-05 03:52:02SlowMist Warns of Large-Scale npm Supply-Chain Attack on Keyv/Cacheable EcosystemSlowMist disclosed on August 5 that it has detected a large-scale npm supply-chain attack affecting the Keyv/Cacheable ecosystem. Attackers have published more than 2,000 malicious package versions, including keyv@6.0.0. Keyv is a widely used key-value storage abstraction layer supporting Redis, SQLite, PostgreSQL, MongoDB and other backends, with roughly 127 million weekly downloads, creating potentially broad downstream supply-chain risk. The attack closely resembles the Shai-Hulud npm worm campaign, indicating strong automation and self-propagation. Potential malicious behaviors include credential theft, environment variable exfiltration, CI/CD secret leakage, remote payload delivery, and lateral movement through compromised development environments. SlowMist recommends security teams immediately identify and remove affected versions, upgrade to verified safe versions, review dependency lock files and build logs, monitor anomalous outbound connections, rotate potentially exposed credentials, and rebuild environments from trusted sources if compromise is suspected.1870