{"rewrite":{"id":"r_7d0001762dd3bb0035aa60d0","clusterId":"c_c6efa9f0853fb56eb82aded3","slug":"npm-supply-chain-attack-hits-434-packages-with-2-billion-monthly-installs","model":"deepseek-v4-flash:free","headline":"Npm Supply Chain Attack Hits 434 Packages With 2 Billion Monthly Installs","summary":"A supply chain attack on npm has compromised at least 434 packages and 1,381 versions, with combined monthly installs exceeding 2 billion. Malware steals credentials and spreads via stolen npm tokens. Keyv, flat-cache, and file-entry-cache are among the affected packages.","whyItMatters":"The attack exploited legitimate publishing infrastructure and a maintainer's account to inject credential-stealing malware into hundreds of widely used packages, with a combined reach of over 2 billion monthly installs.","webCardHtml":"\u003cp\u003eThe attack began with the GitHub account of a developer who manages Keyv, a key-value storage library. The attacker added malicious files directly to the main branch and published a new version using GitHub Actions, so the tampered packages carried official signatures.\u003c/p\u003e\u003cp\u003eCompromised versions include Keyv 6.0.0, flat-cache 6.1.24, and file-entry-cache 11.1.6, each with hundreds of millions of monthly downloads. The malware, delivered via setup.mjs, downloads Bun and runs Math_Symbol.js, which steals npm, GitHub, AWS, Kubernetes, and Vault credentials, plus SSH keys and database info.\u003c/p\u003e\u003cp\u003eStolen data was encrypted and sent to public GitHub repositories. The malware also used stolen npm tokens to republish other packages, spreading beyond the original maintainer\u0026#39;s projects.\u003c/p\u003e","blueskyPost":"Supply chain attack on npm: 434 packages, 1.3k+ versions compromised, 2B+ monthly installs. Malware steals credentials and self-propagates. Keyv, flat-cache, file-entry-cache hit.","twitterPost":"Supply chain attack on npm: 434 packages, 1,381 versions compromised, 2B+ monthly installs. Malware steals credentials and self-propagates. Keyv, flat-cache, file-entry-cache hit.","threadsPost":null,"newsletterBlurb":"A large-scale supply chain attack on npm has compromised hundreds of packages with billions of monthly installs. Malware steals credentials and spreads via stolen tokens. Keyv, flat-cache, and file-entry-cache are among the affected.","attributionJson":"[{\"source\":\"GIGAZINE\",\"url\":\"https://gigazine.net/news/20260805-npm-supply-chain-attack/\",\"title\":\"Large-scale supply chain attack targets popular npm packages with over 2 billion combined monthly installs\"}]","lintFlagsJson":null,"lintHits":0,"costUsd":0,"inputTokens":4567,"outputTokens":566,"status":"published","repairAttempts":0,"nextRepairAt":null,"factsAttemptedAt":1786326606,"createdAt":"2026-08-10T01:32:21.000Z","publishedAt":"2026-08-10T01:36:47.000Z","updatedAt":"2026-08-10T01:32:21.000Z"},"cluster":{"id":"c_c6efa9f0853fb56eb82aded3","canonicalTitle":"合計月間インストール数20億回超の人気npmパッケージ群を狙った大規模サプライチェーン攻撃が発生","representativeArticleId":"a_1c881f2fb8b7ea5a92377036","sourceCount":1,"writtenSourceCount":1,"writeAttempts":0,"isSolo":true,"entitiesJson":"{\"anime_titles\":[],\"manga_titles\":[],\"work_titles\":[],\"studios\":[],\"people\":[],\"type\":\"news\",\"domain\":\"other\",\"is_roundup\":false}","contentType":"news","status":"published","firstSeenAt":"2026-08-05T02:25:00.000Z","lastSeenAt":"2026-08-05T02:25:00.000Z","updatedAt":"2026-08-10T01:36:47.000Z"},"attribution":[{"source":"GIGAZINE","url":"https://gigazine.net/news/20260805-npm-supply-chain-attack/","title":"合計月間インストール数20億回超の人気npmパッケージ群を狙った大規模サプライチェーン攻撃が発生"}],"entities":{"anime_titles":[],"manga_titles":[],"work_titles":[],"studios":[],"people":[],"type":"news","domain":"other","is_roundup":false},"keyFacts":null}
