keyv / cacheable family hijacked in Shai-Hulud "Here We Go Again" worm
On 2026-08-04 a compromised maintainer account pushed a preinstall credential stealer into the keyv / cacheable family and the worm spread via stolen npm tokens across ~2B monthly installs. Releases were cut from main, so npm signed them with valid provenance. Verified count as of the Wiz IOC feed: 443 npm packages across 2,235 versions; SafeDep's registry-backed telemetry puts the total at 1,684 versions across 420 names tied to nine orgs.
Versions named here: 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14, 6.3.15, 6.3.16, 6.3.17, 6.3.18, 6.3.19, 6.3.20, 6.3.21, 6.3.22, 6.3.23, 6.3.24, 6.3.25, 6.3.26, 6.3.27, 6.3.28, 6.3.29, 6.3.30, 6.3.31, 6.3.32, 6.3.33