The GitHub account of the maintainer of the key-value database keyv was compromised on August 4 as part of a Shai-Hulud supply chain attack. While most of the affected packages have since been removed, the attack carries enormous potential for damage. It extends to the entire keyv package family, which collectively garners over 2 billion downloads per month.
Among the affected npm packages, in addition to keyv 6.0.0, which averages around 600 million downloads per month, are the following other packages from the keyv maintainer: flat-cache 6.1.24, file-entry-cache 11.1.6, cacheable-request 13.0.20, cacheable 2.5.1, @cacheable/memory 2.2.1, cache-manager 7.2.10, @cacheable/node-cache 3.1.2, and @cacheable/utils 2.5.1.
Through these core packages, the worm actively spread to packages from other maintainers and organizations, such as @deliveroo/reevent, @or-sdk/invitations, @picsart/ai-sdk, @qlik/embed-runtime, and picasso.js.
On August 5, IT researchers from Aikido Security identified 1381 malicious versions of 444 npm packages. Socket's live tracker now counts over 2400 infected package artifacts. The compromised packages contain a mini Shai-Hulud variant, which StepSecurity has named ChainDrop.











