npm Packages Hijacked in Supply Chain Attack
Reported 04 Aug 2026 by otx · Severity: medium
Multiple npm packages in the keyv/cacheable ecosystem were compromised after attackers gained control of a GitHub maintainer account. Beginning at 9:00 UTC on August 4, 2026, the attacker introduced IDE persistence mechanisms and published malicious versions that propagated to ov