CYBERSECURITYTRACKER
TRACKING7,004 stories in this site build1,474 vulnerability news stories in this site build
Permanent story citation

keyv and cacheable npm Package Hijacked in Supply Chain Attack

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3798

As cited

Copy frozen at (site build).

breaches incidents

keyv and cacheable npm Package Hijacked in Supply Chain Attack

Wiz Research has detected an active supply chain attack targeting multiple npm packages in the keyv and cacheable ecosystems. The incident appears to involve unauthorized control of these widely used caching libraries.

Why it matters: Developers using keyv or cacheable packages in production systems face potential code injection and compromise of their applications; immediate verification of package versions and origins is necessary.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary