importantSYS.SOURCE: Aikido.dev• 2026-08-04T11:01:37Z
Compromised npm Packages Keyv and Flattened Caching Libraries Expose Credential-Stealing Supply Chain Attack
Attackers compromised the GitHub account of the Keyv library maintainer, injecting credential-stealing malware into multiple npm packages. The malicious code, delivered via compromised packages, exfiltrates secrets to a public GitHub repository and spreads to other maintainers.
*** END OF TRANSMISSION ***