Supply Chain Compromise Affecting keyv and cacheable npm Packages

Reported 05 Aug 2026 by otx · Severity: medium

An active supply chain attack has compromised the keyv and cacheable npm packages, affecting tens of millions of weekly downloads. On August 4, 2026, at least ten packages were published with malicious preinstall hooks that download a Bun runtime and execute obfuscated payloads.