Keyv/Cacheable Ecosystem Targeted in Major npm Supply-Chain Attack; 2,000+ Malicious Package Versions Published

AI مارکیٹ کا خلاصہ
SlowMist reports a large-scale npm supply-chain attack hitting the widely used Keyv/Cacheable ecosystem, with 2,000+ malicious package versions and major downstream exposure. The risk of credential theft, CI/CD secret leakage, and remote payload delivery raises operational and counterparty risk across crypto and fintech teams reliant on JavaScript tooling. Near term, this can dampen risk appetite and increase security-driven disruption as projects rotate credentials and rebuild environments.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
BTC/USDT+0.83%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
ChainCatcher reports that SlowMist monitoring shows MistEye has identified a large-scale npm supply-chain attack aimed at the Keyv/Cacheable ecosystem. The attacker is said to have published more than 2,000 malicious package versions, including keyv@6.0. Keyv is a widely used key-value storage abstraction library with support for Redis, SQLite, PostgreSQL, and MongoDB. With roughly 127 million weekly downloads, the incident creates substantial downstream supply-chain risk. SlowMist noted the tactics closely resemble prior ShaiHulud npm worm activity, suggesting a highly automated, scalable campaign. Suspected capabilities include credential theft, environment variable leakage, CI/CD secret exposure, remote payload delivery, and lateral movement via compromised development environments. Security teams are advised to promptly identify and remove impacted versions, upgrade to verified safe releases, review dependency lock files and build logs, monitor for suspicious outbound connections, rotate any potentially exposed credentials, and rebuild affected environments if compromise is confirmed.