- Sources: scope, timeline, analysis, discussion
- Summary: The keyv maintainer's GitHub account was compromised on 2026-08-04. Socket reconstructs the timeline from npm registry publish timestamps: keyv@6.0.0 published at 09:35 UTC as the first version carrying a malicious preinstall hook, and the cacheable family followed in a burst between 10:09 and 10:14 UTC. Aikido names the first-generation affected versions as flat-cache 6.1.24, file-entry-cache 11.1.6, cacheable-request 13.0.20, cacheable 2.5.1 and cache-manager 7.2.10, and its 13:37 CEST update counts 434 affected packages across 1381 versions with more than 2 billion monthly installs combined. Socket, Wiz and Aikido agree on the mechanism, the file hashes and the exfiltration marker string. The full affected-version list is still moving.
- Why it matters: The compromised packages sit deep in ordinary dependency trees rather than in direct dependencies, and Socket names the common chain as eslint to file-entry-cache to flat-cache to keyv, so most affected projects never installed any of them on purpose. Any machine that ran an install script against an affected version should be treated as compromised, including CI runners holding cloud and registry credentials.
- Follow-up: Track the affected-version lists as the package count moves.
send feedback on this story