P.01The Keyv and Cacheable npm Attack: 2,234 Poisoned Package Versions in One Day
A compromised maintainer account on August 4 turned keyv and cacheable into a self-propagating npm worm that stole cloud, CI, and GitHub credentials from packages with tens of millions of weekly downloads. Here's what happened and how to check if you were hit.















