Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)

2026-08-05T19:23:42Z73b9a132585861bdbc87a5a95b5e49023425d9d1900bee0dd08e3dcdebd9fbc9
CI/CDGitHub-PATbuild-hostcacheablecloud-credentialscredential-theftincident-responsekeyvmalicious-packagenpmsupply-chain-compromisetoken-revocation

What happened

SANS ISC reports an ongoing npm supply-chain compromise affecting the keyv/cacheable packages. Malicious code executed on build hosts and appears designed to trigger when stolen npm, GitHub, or cloud credentials are revoked, so immediate token revocation may activate the payload. The incident requires coordinated containment, credential-preservation strategy, forensic analysis, and monitoring. No CVE is identified in the provided feed.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
73b9a132585861bdbc87a5a95b5e49023425d9d1900bee0dd08e3dcdebd9fbc9
Enrichment time
2026-08-05T19:23:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.