datadog-security-labs · Crawled Aug 4, 2026

Worm compromises hundreds of popular npm packages

4 IoCs
Read original article ↗

AI Summary

On August 4, 2026, a worm compromised several high-profile npm packages, including keyv, file-entry-cache, and flat-cache, each with around 150 million monthly downloads. The malicious commit (174f6a5) in the keyv package introduced a backdoor designed to propagate to adjacent npm packages, indicating a supply chain attack aimed at widespread distribution. The campaign represents a significant open-source software supply chain compromise with potential for broad impact due to the popularity of the affected packages.

AI-extracted · verify before operational use

Indicators of Compromise 4 extracted

Type Value Detail
GitHub Repo keyv/keyv Details →
Package keyv Details →
Package file-entry-cache Details →
Package flat-cache Details →