keyv / cacheable family hijacked in Shai-Hulud "Here We Go Again" worm
On 2026-08-04 a compromised maintainer account pushed a preinstall credential stealer into the keyv / cacheable family and the worm spread via stolen npm tokens across ~2B monthly installs. Releases were cut from main, so npm signed them with valid provenance. Verified count as of the Wiz IOC feed: 443 npm packages across 2,235 versions; SafeDep's registry-backed telemetry puts the total at 1,684 versions across 420 names tied to nine orgs.
Versions named here: 5.2.1, 5.2.2, 5.2.3, 5.2.4, 5.2.5, 5.2.6, 5.2.7, 5.2.8, 5.2.9, 5.2.10, 5.2.11, 5.2.12, 5.2.13, 5.2.14, 5.2.15, 5.2.16