A major software supply chain attack has impacted the JavaScript ecosystem after attackers compromised maintainer accounts and published malicious versions of Keyv, Cacheable, and numerous other npm packages. The malware executes during package installation using npm’s preinstall lifecycle hook and targets a wide range of developer and infrastructure secrets, including GitHub and npm tokens, AWS credentials, HashiCorp Vault authentication data, Kubernetes service account tokens, SSH keys, TLS certificates, and CI/CD secrets. Researchers also found repository-level persistence mechanisms targeting VS Code and Claude Code environments.
You must log in or # to comment.

