keyv / cacheable family hijacked in Shai-Hulud "Here We Go Again" worm
On 2026-08-04 a compromised maintainer account pushed a preinstall credential stealer into the keyv / cacheable family and the worm spread via stolen npm tokens across ~2B monthly installs. Releases were cut from main, so npm signed them with valid provenance. Verified count as of the Wiz IOC feed: 443 npm packages across 2,235 versions; SafeDep's registry-backed telemetry puts the total at 1,684 versions across 420 names tied to nine orgs.
Versions named here: 2.1.3, 2.1.4, 2.1.5, 2.1.6, 2.1.7, 2.1.8, 2.1.9