keyv / cacheable family hijacked in Shai-Hulud "Here We Go Again" worm
On 2026-08-04 a compromised maintainer account pushed a preinstall credential stealer into the keyv / cacheable family and the worm spread via stolen npm tokens across ~2B monthly installs. Releases were cut from main, so npm signed them with valid provenance. Verified count as of the Wiz IOC feed: 443 npm packages across 2,235 versions; SafeDep's registry-backed telemetry puts the total at 1,684 versions across 420 names tied to nine orgs.
Versions named here: 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7