# Keyv and friends compromised in active Shai-Hulud supply chain attack

_Tuesday, August 4, 2026 at 8:00 AM EDT · Security · Latest · Tier 2 — Notable_

![Keyv and friends compromised in active Shai-Hulud supply chain attack — Primary](https://cdn.prod.website-files.com/642adcaf364024654c71df23/6a71ca1f4e190f1129a4d78a_Social_ShaiHulud-Template-Light_16x9.png)

Attackers compromised the GitHub account of the maintainer behind keyv on August 4, 2026, and used that access to inject a credential-stealing worm across the entire package family, the source said. The same maintainer owns cacheable, flat-cache, file-entry-cache, and several other widely-used caching utilities, all of which were swept up in the same attack.

The compromise was carried out by pushing malicious files directly to the main branch and then immediately cutting a new release, meaning the poisoned versions were published to npm with valid provenance signed by GitHub Actions. Compromised packages include keyv 6.0.0, flat-cache 6.1.24, file-entry-cache 11.1.6, and numerous others.

Every package in the family received two new files, setup.mjs and Math_Symbol.js, along with a preinstall script added to each package.json. Anyone who ran npm install against an affected version would have had setup.mjs execute automatically before their install completed. The payload harvests secrets from the victim's environment, encrypts the findings, and exfiltrates them to a public GitHub repository whose description reads "Shai-Hulud: Here We Go Again".

Update August 4, 2026, 13:37 CEST: At least 434 packages across 1381 versions have been compromised by the worm, with a combined total of over 2 billion monthly installs at the time of writing. The payload also contains worm-like propagation functionality to infect packages of other maintainers that have installed one of the compromised packages.

## Sources

- [aikido.dev](https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack)

---
Canonical: https://techandbusiness.org/newswire/k-q1iRzR4CJ_-n5Nz_sMsc
Retrieved: 2026-08-04T19:35:45.365Z
Publisher: Tech & Business (techandbusiness.org)
