THREATOPS
THREAT OPSThreat News › Compromised keyv Maintainer Account Triggers Massive npm Supply Chain Attack

Compromised keyv Maintainer Account Triggers Massive npm Supply Chain Attack

loworca_securityPublished 2026-08-05

<p>A compromised GitHub maintainer account was used to publish malicious versions of 10 widely-used npm packages in the keyv and cacheable ecosystem, collectively downloaded over 619 million times per month. The attack, attributed to the TeamPCP threat group, deployed a descendant of the &#8220;Mini&#8221; Shai-Hulud malware family that harvests cloud credentials, GitHub tokens, SSH keys, [&#8230;

MITRE ATT&CK techniques

Original source: https://orca.security/resources/blog/compromised-keyv-npm-supply-chain-attack/