
Keyv and Cacheable npm packages compromised in active supply-chain attack
On August 4, 2026, a self-propagating worm began publishing malicious versions of the npm packages keyv and cacheable and their common dependencies. This keyv/cacheable supply-chain attack, tracked as keyv-shai-hulud, is still developing as we publish, and the list of affected npm packages has grown through the day. Below we cover what we know so far, how to check whether your organization is exposed, and the controls that stop this class of attack from reaching your builds…












