Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

npm Packages Hijacked in Supply Chain Attack

0
Medium
Published: 08/04/2026 (08/04/2026, 18:15:36 UTC)
Source: AlienVault OTX General

Description

Multiple npm packages in the keyv/cacheable ecosystem were compromised after attackers gained control of a GitHub maintainer account. Beginning at 9:00 UTC on August 4, 2026, the attacker introduced IDE persistence mechanisms and published malicious versions that propagated to over 400 distinct packages. The payload is a descendant of the 'Mini' Shai-Hulud malware family, sharing similarities with TeamPCP and antv campaigns. It targets sensitive data including cloud credentials, infrastructure secrets, developer credentials, AI configuration files, and cryptocurrency wallets. The malware uniquely retrieves command-and-control domains from an Ethereum smart contract rather than embedding them, allowing infrastructure updates without modifying the payload. Data is exfiltrated through GitHub repositories created under compromised identities. The campaign demonstrates sophisticated supply chain attack techniques targeting developer environments and CI/CD pipelines.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 11:28:41 UTC

Technical Analysis

Attackers compromised a GitHub maintainer account associated with multiple npm packages in the keyv/cacheable ecosystem, beginning August 4, 2026. They published malicious package versions embedding a payload derived from the Mini Shai-Hulud malware family, which shares characteristics with TeamPCP and antv campaigns. The malware targets sensitive data such as cloud and developer credentials, AI configuration files, infrastructure secrets, and cryptocurrency wallets. Uniquely, it obtains command-and-control domains from an Ethereum smart contract, allowing dynamic infrastructure updates without altering the payload. Exfiltrated data is sent to GitHub repositories created under compromised identities. Over 400 distinct npm packages were affected, demonstrating advanced supply chain attack techniques focused on developer environments and CI/CD pipelines.

Potential Impact

The attack compromises the integrity of widely used npm packages, potentially affecting numerous downstream projects and developers. Sensitive data including cloud credentials, infrastructure secrets, developer credentials, AI configuration files, and cryptocurrency wallets may be stolen. The dynamic retrieval of command-and-control domains from an Ethereum smart contract complicates detection and mitigation. The use of GitHub repositories for data exfiltration under compromised identities further obscures attacker activity. This poses a significant risk to software supply chains and developer environments.

Defensive Guidance

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until official fixes or advisories are available, developers should audit dependencies in the keyv/cacheable ecosystem and avoid using suspicious or newly published package versions from August 4, 2026, onward. Review GitHub maintainer account security and rotate credentials. Monitor for unusual activity in developer environments and CI/CD pipelines related to these packages. Follow vendor and security community updates for remediation and detection tools.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack"]
Adversary
Shai-Hulud
Pulse Id
6a722c48758de52f5ea94f17
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainnpm-cache.com
domainpypi-get.com
domainjs-mirror.com
domaingo.getblock.io

Hash

ValueDescriptionCopy
hash35a672cf34b996b91f3e1c28cbf3a05a37e036e4
hash686aa40d0fc22c8d569494543a0f891f359f2f99
hashf525d52ceb966516686b482d3dc0137028cc6a63

Threat ID: 6a7301c5bf8831d539a3dd1a

Added to database: 08/05/2026, 09:26:29 UTC

Last enriched: 08/05/2026, 11:28:41 UTC

Last updated: 08/05/2026, 20:15:05 UTC

Views: 21

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses