On August 4, 2026, attackers compromised the GitHub account of the maintainer of the Keyv library, which has approximately 127 million weekly npm downloads. The attackers injected a credential-stealing worm into Keyv and several other widely-used packages owned by the same maintainer, including Cacheable, Flat-cache, and File-entry-cache.
aikido.dev
7 min
8/4/2026
On August 4, 2026, attackers compromised the GitHub account of the maintainer of the Keyv library, which has approximately 127 million weekly npm downloads. The attackers injected a credential-stealing worm into Keyv and several other widely-used packages owned by the same maintainer, including Cacheable, Flat-cache, and File-entry-cache.
aikido.dev
7 min
8/4/2026
On August 4, 2026, attackers compromised the GitHub account of the maintainer of the Keyv library, which has approximately 127 million weekly npm downloads. The attackers injected a credential-stealing worm into Keyv and several other widely-used packages owned by the same maintainer, including Cacheable, Flat-cache, and File-entry-cache.
aikido.dev
7 min
8/4/2026
No more articles to load