As cited
Copy frozen at (site build).
breaches incidents
keyv and cacheable npm Package Hijacked in Supply Chain Attack
Wiz Research has detected an active supply chain attack targeting multiple npm packages in the keyv and cacheable ecosystems. The incident appears to involve unauthorized control of these widely used caching libraries.
Why it matters: Developers using keyv or cacheable packages in production systems face potential code injection and compromise of their applications; immediate verification of package versions and origins is necessary.
- Source published
- First seen by Cybersecurity Tracker