Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)

0
Medium
Published: 08/05/2026 (08/05/2026, 17:56:15 UTC)
Source: SANS ISC Handlers Diary

Description

When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle the cloud keys. That reflex has been correct in almost every supply-chain incident I have worked. In the keyv/cacheable compromise that has been unfolding since yesterday, it is the one thing you should not do first — because revoking the stolen token is exactly what arms the payload.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 17:56:45 UTC

Technical Analysis

On August 4, 2026, attackers compromised the maintainer accounts of the widely used npm packages keyv and cacheable, publishing trojanized versions containing a preinstall hook that downloads a standalone Bun runtime and runs obfuscated second-stage code. This code harvests AWS instance metadata, cloud keys, Vault tokens, Kubernetes service-account tokens, GitHub Actions secrets, npm tokens, and other private keys or bearer tokens found on disk. Using stolen npm tokens, the payload propagates by injecting the malicious hook into other packages it can publish, creating a worm that rapidly expanded to over 440 packages and 2000+ versions. The attack also installs a host-level dead-man's switch as a macOS LaunchAgent or Linux systemd user service that monitors the validity of stolen GitHub tokens. If a token is revoked (causing an HTTP 4xx response), the switch executes a remote attacker-controlled handler, then self-destructs. This design punishes the typical remediation step of immediate token revocation. The attack vector includes execution triggered by opening the source repository in IDEs or AI coding agents, not just by running npm install. The recommended incident response is to isolate the host from the network first, preserve evidence, eradicate the malware and persistence, then rotate and revoke credentials in the prescribed order to avoid triggering the dead-man's switch.

Potential Impact

The compromise allows attackers to steal a wide range of sensitive credentials including cloud keys, GitHub tokens, npm tokens, Vault tokens, Kubernetes tokens, and private keys from affected hosts. The worm-like propagation mechanism enables rapid spread across thousands of npm package versions, increasing the attack surface. The dead-man's switch mechanism can trigger unknown malicious actions remotely if stolen GitHub tokens are revoked prematurely, potentially causing data destruction or re-implantation. The attack vector includes execution without explicit installation, increasing the risk of unnoticed compromise. The incident can affect build hosts, developer machines, CI runners, and any system that clones or opens affected repositories. The complexity and stealth of the attack complicate detection and remediation.

Defensive Guidance

The vendor advisory and analysis recommend first isolating affected hosts from the network to prevent the dead-man's switch from triggering. Do not power off the host to preserve volatile evidence. Collect and preserve files related to the dead-man's switch and payload for forensic analysis. Eradicate the malware by killing the watcher process, unloading the LaunchAgent or disabling the systemd unit, removing persistence files and IDE hooks, and clearing package caches. Only after thorough cleanup should you rotate and revoke credentials, starting with the npm token to stop propagation, followed by GitHub tokens, cloud keys, Vault tokens, Kubernetes tokens, and any other secrets found. Revoke tokens rather than merely rotating them. Audit for unauthorized repository changes, unexpected npm publishes, and suspicious credential use during the exposure window. Rebuild CI runners and affected hosts rather than attempting to clean them due to arbitrary code execution risks. Use the provided open-source scanner tool to assist with triage and detection.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.82,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://isc.sans.edu/diary/rss/33218","fetched":true,"fetchedAt":"2026-08-05T17:56:13.034Z","wordCount":1445}

Threat ID: 6a73793dbf8831d5393d5ed0

Added to database: 08/05/2026, 17:56:13 UTC

Last enriched: 08/05/2026, 17:56:45 UTC

Last updated: 08/05/2026, 23:18:24 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses