Skip to content

feat(threat_intel): add keyv and Cacheable compromise catalog - #71

Open
ronheichman wants to merge 1 commit into
perplexityai:mainfrom
ronheichman:advisory-catalog/keyv-cacheable-2026-08-04
Open

feat(threat_intel): add keyv and Cacheable compromise catalog#71
ronheichman wants to merge 1 commit into
perplexityai:mainfrom
ronheichman:advisory-catalog/keyv-cacheable-2026-08-04

Conversation

@ronheichman

@ronheichman ronheichman commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Why

The August 4 keyv and Cacheable compromise shipped a credential-stealing, self-propagating npm preinstall payload through widely used caching dependencies. Removed malicious releases can still remain on developer machines and CI runners, so endpoint scans need exact package/version indicators.

What

  • Adds keyv-cacheable-compromise-2026-08-04.json with 11 OSV-corroborated npm packages and all 13 affected versions.
  • Documents the catalog methodology and scope at the root: this is a reviewed subset of Socket's evolving campaign tracker, which currently contains 4,474 artifacts across 455 packages.
  • Links both the Socket report and live campaign tracker from the catalog index.

The package set is limited to entries backed by OSV malicious-package records whose affected releases are also absent from the npm registry. In particular, @thiennq/docs-viewer includes 1.6.2, 1.6.3, and 1.6.4 from MAL-2026-11952.

Proof

An end-to-end scanner smoke test against @thiennq/docs-viewer@1.6.4 emitted a critical finding with exact name+version match evidence.

@ronheichman ronheichman changed the title feat(threat_intel): keyv and Cacheable namespace compromise catalog (11 npm packages) Add supply-chain exposure catalog https-socket-dev-blog-popular-npm-packages-in-the-keyv-and-cacheable-na-cfb10520 Aug 17, 2026
@ronheichman

Copy link
Copy Markdown
Contributor Author

@thom-pplx requesting your review on this catalog.

The reviewer field cannot be set from this account: the PR comes from a fork and ronheichman has pull-only access on this repo, so RequestReviewsByLogin is refused. Flagging by mention instead.

Catalog the 11 OSV-corroborated npm packages from the August 4 compromise, including all 13 affected versions. Document that this is a reviewed subset of Socket’s broader evolving campaign tracker.
@adel-pplx
adel-pplx force-pushed the advisory-catalog/keyv-cacheable-2026-08-04 branch from fde02f8 to 0be53fd Compare August 21, 2026 14:28
@adel-pplx adel-pplx changed the title Add supply-chain exposure catalog https-socket-dev-blog-popular-npm-packages-in-the-keyv-and-cacheable-na-cfb10520 feat(threat_intel): add keyv and Cacheable compromise catalog Aug 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants