- Sources: analysis, discussion
- Summary: Endor Labs states that the first wave was published through the Cacheable project's own GitHub Actions OIDC trusted publishing pipeline, after a commit to main added a preinstall hook. Endor puts the first wave's seed packages at roughly 515 million weekly downloads from the npm last-week API on 2026-08-04, and states that keyv, flat-cache and file-entry-cache alone exceed 450 million. Endor also states those figures sum package-level traffic and overlap in dependency trees, so they show the wave's reach rather than a count of distinct installs. Those tarballs carry valid npm signatures and SLSA provenance. Endor states the campaign then spread to other maintainers' packages typically via stolen npm publishing tokens and without provenance. Endor counts 384 packages across 1,136 versions and describes that as a floor. Aikido's count published on 2026-08-04 was 434 packages across 1,381 versions. The two counts are not reconciled and both vendors describe their lists as moving, so no single total is asserted here.
- Why it matters: Provenance works here as a wave discriminator and not as a filter, so a defender who quarantines unprovenanced tarballs catches the token-stolen spread and installs the seed compromise.
- Follow-up: Track whether the vendor package and version counts converge, and whether npm changes trusted publishing to cover source integrity.
send feedback on this story