From 0be53fd225ffd8f25665c4ef188b24c042bea629 Mon Sep 17 00:00:00 2001 From: Ron Heichman Date: Mon, 17 Aug 2026 11:56:52 -0500 Subject: [PATCH] feat(threat_intel): add keyv and Cacheable compromise catalog MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Catalog the 11 OSV-corroborated npm packages from the August 4 compromise, including all 13 affected versions. Document that this is a reviewed subset of Socket’s broader evolving campaign tracker. --- threat_intel/README.md | 1 + .../keyv-cacheable-compromise-2026-08-04.json | 129 ++++++++++++++++++ 2 files changed, 130 insertions(+) create mode 100644 threat_intel/keyv-cacheable-compromise-2026-08-04.json diff --git a/threat_intel/README.md b/threat_intel/README.md index 9f702dd..599753c 100644 --- a/threat_intel/README.md +++ b/threat_intel/README.md @@ -12,6 +12,7 @@ the entries against current advisories before production use. | File | Campaign | Source | |---|---|---| +| [`keyv-cacheable-compromise-2026-08-04.json`](keyv-cacheable-compromise-2026-08-04.json) | keyv and Cacheable npm compromise (maintainer account takeover; 11 OSV-corroborated packages / 13 versions, malicious `preinstall` hook staging a credential stealer); this is a reviewed subset of Socket's broader evolving campaign tracker | [Socket report, 2026-08-04](https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain); [campaign tracker](https://socket.dev/supply-chain-attacks/keyv-and-cacheable-compromise) | | [`mastra-2026-06-17.json`](mastra-2026-06-17.json) | Mastra npm supply-chain compromise (141 packages / 141 versions across `@mastra/*` plus `create-mastra` and the `easy-day-js@1.11.22` typosquat dependency that delivered a cross-platform infostealer via postinstall) | [Socket, 2026-06-17](https://socket.dev/blog/mastra-npm-packages-compromised) | | [`mini-shai-hulud-leoplatform-2026-06-24.json`](mini-shai-hulud-leoplatform-2026-06-24.json) | Mini Shai-Hulud / Miasma (Hades variant) LeoPlatform/RStreams wave (compromised `czirker` npm account; 26 npm packages + 1 Go module / 27 versions; "Phantom Gyp" `binding.gyp` install hook, Bun-staged infostealer, "Alright Lets See If This Works" dead-drop marker) | [Socket, 2026-06-24](https://socket.dev/blog/miasma-mini-shai-hulud-hits-leoplatform-npm-packages-go-ecosystem); [OX Security, 2026-06-24](https://www.ox.security/blog/alright-lets-see-if-this-works-shai-hulud-miasma-hades-variant-spreads-on-npm/) | | [`mini-shai-hulud.json`](mini-shai-hulud.json) | Mini/Shai-Hulud May 2026 npm and PyPI compromise (OX Security affected-package table) | Cross-checked against Fleet, Socket, Snyk, Mistral, TanStack, The Hacker News | diff --git a/threat_intel/keyv-cacheable-compromise-2026-08-04.json b/threat_intel/keyv-cacheable-compromise-2026-08-04.json new file mode 100644 index 0000000..93e93a6 --- /dev/null +++ b/threat_intel/keyv-cacheable-compromise-2026-08-04.json @@ -0,0 +1,129 @@ +{ + "schema_version": "0.2.0", + "_comment": "August 4, 2026 keyv and Cacheable npm compromise. This catalog intentionally contains the 11 packages corroborated by OSV malicious-package records and removed affected versions in the npm registry: 11 packages / 13 exact versions. Socket's evolving campaign tracker currently reports 4,474 artifacts across 455 packages and is broader than this reviewed subset. Sources: https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain, https://socket.dev/supply-chain-attacks/keyv-and-cacheable-compromise, and OSV records MAL-2026-11523, MAL-2026-11524, MAL-2026-11558, MAL-2026-11559, MAL-2026-11560, MAL-2026-11561, MAL-2026-11952, MAL-2026-11963, MAL-2026-11964, MAL-2026-11970, and MAL-2026-11971.", + "entries": [ + { + "id": "https-socket-dev-blog-popular-npm-packages-in-the-keyv-and-cacheable-na-cfb10520-npm-cacheable-memory", + "name": "@cacheable/memory (keyv and cacheable supply chain attack)", + "ecosystem": "npm", + "package": "@cacheable/memory", + "versions": [ + "2.2.1" + ], + "severity": "critical", + "source": "https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain" + }, + { + "id": "https-socket-dev-blog-popular-npm-packages-in-the-keyv-and-cacheable-na-cfb10520-npm-cacheable-net", + "name": "@cacheable/net (keyv and cacheable supply chain attack)", + "ecosystem": "npm", + "package": "@cacheable/net", + "versions": [ + "2.1.1" + ], + "severity": "critical", + "source": "https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain" + }, + { + "id": "https-socket-dev-blog-popular-npm-packages-in-the-keyv-and-cacheable-na-cfb10520-npm-cacheable-node-cache", + "name": "@cacheable/node-cache (keyv and cacheable supply chain attack)", + "ecosystem": "npm", + "package": "@cacheable/node-cache", + "versions": [ + "3.1.2" + ], + "severity": "critical", + "source": "https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain" + }, + { + "id": "https-socket-dev-blog-popular-npm-packages-in-the-keyv-and-cacheable-na-cfb10520-npm-cacheable-utils", + "name": "@cacheable/utils (keyv and cacheable supply chain attack)", + "ecosystem": "npm", + "package": "@cacheable/utils", + "versions": [ + "2.5.1" + ], + "severity": "critical", + "source": "https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain" + }, + { + "id": "https-socket-dev-blog-popular-npm-packages-in-the-keyv-and-cacheable-na-cfb10520-npm-thiennq-docs-viewer", + "name": "@thiennq/docs-viewer (keyv and cacheable supply chain attack)", + "ecosystem": "npm", + "package": "@thiennq/docs-viewer", + "versions": [ + "1.6.2", + "1.6.3", + "1.6.4" + ], + "severity": "critical", + "source": "https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain" + }, + { + "id": "https-socket-dev-blog-popular-npm-packages-in-the-keyv-and-cacheable-na-cfb10520-npm-cache-manager", + "name": "cache-manager (keyv and cacheable supply chain attack)", + "ecosystem": "npm", + "package": "cache-manager", + "versions": [ + "7.2.10" + ], + "severity": "critical", + "source": "https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain" + }, + { + "id": "https-socket-dev-blog-popular-npm-packages-in-the-keyv-and-cacheable-na-cfb10520-npm-cacheable", + "name": "cacheable (keyv and cacheable supply chain attack)", + "ecosystem": "npm", + "package": "cacheable", + "versions": [ + "2.5.1" + ], + "severity": "critical", + "source": "https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain" + }, + { + "id": "https-socket-dev-blog-popular-npm-packages-in-the-keyv-and-cacheable-na-cfb10520-npm-cacheable-request", + "name": "cacheable-request (keyv and cacheable supply chain attack)", + "ecosystem": "npm", + "package": "cacheable-request", + "versions": [ + "13.0.20" + ], + "severity": "critical", + "source": "https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain" + }, + { + "id": "https-socket-dev-blog-popular-npm-packages-in-the-keyv-and-cacheable-na-cfb10520-npm-file-entry-cache", + "name": "file-entry-cache (keyv and cacheable supply chain attack)", + "ecosystem": "npm", + "package": "file-entry-cache", + "versions": [ + "11.1.6" + ], + "severity": "critical", + "source": "https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain" + }, + { + "id": "https-socket-dev-blog-popular-npm-packages-in-the-keyv-and-cacheable-na-cfb10520-npm-flat-cache", + "name": "flat-cache (keyv and cacheable supply chain attack)", + "ecosystem": "npm", + "package": "flat-cache", + "versions": [ + "6.1.24" + ], + "severity": "critical", + "source": "https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain" + }, + { + "id": "https-socket-dev-blog-popular-npm-packages-in-the-keyv-and-cacheable-na-cfb10520-npm-keyv", + "name": "keyv (keyv and cacheable supply chain attack)", + "ecosystem": "npm", + "package": "keyv", + "versions": [ + "6.0.0" + ], + "severity": "critical", + "source": "https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain" + } + ] +}