Skip to main content
Sign in

keyv / cacheable npm Supply Chain Attack — TeamPCP Mini Shai-Hulud (August 2026)

avoid.net/keyv-cacheable-npm-supply-chain-attack-teampcp-mini-shai-hulud-august-20260/100·92% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·pHfFNv…ww42

Summary

On August 4, 2026, the GitHub account of Jared Wray (jaredwray), maintainer of the keyv and cacheable npm package ecosystems, was compromised, enabling attackers to inject the Mini Shai-Hulud credential-stealing worm into at least 11 core packages representing over two billion combined monthly downloads. A self-propagating worm mechanism subsequently expanded the blast radius to more than 400 additional npm packages across 2,234 poisoned versions. The attack is attributed to the TeamPCP threat group and represents one of the largest npm supply chain compromises on record by download volume.

Have evidence about keyv / cacheable npm Supply Chain Attack — TeamPCP Mini Shai-Hulud (August 2026)?

Timeline(14 events)

November 2025

TeamPCP threat group first observed conducting cloud-native cryptomining and credential theft campaigns.

Pluto Security — TeamPCP: The supply chain attack story so far

19 March 2026

TeamPCP Phase 2/3: 76 of 77 Trivy GitHub Action tags force-pushed with SANDCLOCK credential stealer; CanisterWorm infected 66+ npm packages using ICP blockchain for C2.

Palo Alto Unit 42 — Weaponizing the Protectors: TeamPCP's Multi-Stage Supply Chain Attack

2 April 2026

CERT-EU officially attributed the breach of the European Commission's AWS environment to TeamPCP.

Pluto Security — TeamPCP: The supply chain attack story so far

11 May 2026

TeamPCP Phase 5: TanStack attack — 84 malicious versions published across 42 @tanstack/* npm packages via OIDC token theft.

Snyk — TanStack npm Packages Hit by Mini Shai-Hulud

12 May 2026

TeamPCP open-sourced the Shai-Hulud worm toolkit under the description 'A Gift From TeamPCP', enabling potential derived operators.

Pluto Security — TeamPCP: The supply chain attack story so far

4 August 2026

09:02 UTC: First malicious commit pushed to keyv GitHub repository by attacker using compromised jaredwray account credentials.

Datadog Security Labs — Worm compromises hundreds of popular npm packages

4 August 2026

09:04 UTC: GitHub Actions bot commits add .claude/settings.json and .vscode/tasks.json IDE persistence hooks to repository branches.

Datadog Security Labs — Worm compromises hundreds of popular npm packages

4 August 2026

09:35 UTC: Malicious keyv@6.0.0 published to npm registry with valid SLSA provenance attestation.

Snyk — Inside the keyv npm Supply Chain Compromise

4 August 2026

09:40 UTC (approx.): Socket's automated scanner flags malicious code in keyv@6.0.0 approximately 5 minutes 18 seconds after publication.

Socket — Popular npm Packages in the keyv and Cacheable Namespaces Compromised

4 August 2026

10:06–10:28 UTC: Nine additional compromised Cacheable-family packages and ecto@5.0.1 published in rapid succession.

Datadog Security Labs — Worm compromises hundreds of popular npm packages

4 August 2026

10:18–10:20 UTC (approx.): Public warnings spread across security channels about the attack.

The Hacker News — Keyv-Linked npm Worm Poisons Hundreds of Packages

4 August 2026

10:39 UTC (approx.): npm begins removing compromised versions; worm propagation burst completes with approximately 2,234 poisoned versions across 444 packages.

The Hacker News — Keyv-Linked npm Worm Poisons Hundreds of Packages

4 August 2026

By 17:40 IST: Previous clean versions restored as 'latest' for at least nine primary affected packages.

The Hacker News — Keyv-Linked npm Worm Poisons Hundreds of Packages

5 August 2026

Security researchers report total impact of 444+ distinct packages and 1,381–2,234 poisoned versions; combined downstream exposure confirmed at over 2 billion monthly installs.

Aikido Security — Keyv and friends compromised in npm supply chain attack
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 18 of 18 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/8/2026, 12:06:39 PM

last updated: 8/27/2026, 3:24:19 AM

5 views

avoid.net — verified advice for a post-truth world