On August 4, 2026, attackers compromised the GitHub account of the maintainer of the Keyv library, which has approximately 127 million weekly npm downloads. The attackers injected a credential-stealing worm into Keyv and several other widely-used packages owned by the same maintainer, including Cacheable, Flat-cache, and File-entry-cache.
aikido.dev
7 min
10h ago
On August 4, 2026, attackers compromised the GitHub account of the maintainer of the Keyv library, which has approximately 127 million weekly npm downloads. The attackers injected a credential-stealing worm into Keyv and several other widely-used packages owned by the same maintainer, including Cacheable, Flat-cache, and File-entry-cache.
aikido.dev
7 min
10h ago
On August 4, 2026, attackers compromised the GitHub account of the maintainer of the Keyv library, which has approximately 127 million weekly npm downloads. The attackers injected a credential-stealing worm into Keyv and several other widely-used packages owned by the same maintainer, including Cacheable, Flat-cache, and File-entry-cache.
aikido.dev
7 min
10h ago
No more articles to load