Supply Chain Compromise Affecting keyv and cacheable npm Packages

Reported 06 Aug 2026 by otx · Severity: medium

An active supply chain attack has compromised the keyv and cacheable npm packages, affecting tens of millions of weekly downloads. The attack began on August 4, 2026, when the maintainer account Jaredwray was compromised, enabling attackers to publish malicious code across multip