An active npm supply chain compromise affected widely used packages in the keyv and cacheable ecosystems, along with packages owned by other maintainers. At least ten packages were published with a malicious preinstall hook named setup.mjs.
The hook downloads a standalone Bun runtime, runs an obfuscated second-stage payload, collects cloud and CI credentials, and can publish trojanized versions of additional npm packages reachable through a stolen npm token. The affected packages collectively receive tens of millions of weekly downloads, and additional malicious packages may continue to appear.
Evidence indicates that the Jaredwray maintainer account was compromised. Activity began across the keyv and cacheable package families before spreading through stolen npm credentials to packages outside those namespaces.
The malicious payload can:
Collect cloud, CI, GitHub, npm, Vault, and Kubernetes credentials.









