· npm
Keyv and related npm packages hit by a supply-chain worm ↗
Wiz documented malicious releases following a maintainer account compromise. The payload targeted developer and cloud credentials and attempted to spread through package publishing.
Affected versions: keyv 6.0.0; cacheable-request 13.0.20; cache-manager 7.2.10
Packages: keyv · cacheable-request · cache-manager
Source: Wiz Research