Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators npm Packages Hijacked in Supply Chain Attack

686aa40d0fc22c8d569494543a0f891f359f2f99

TLP:CLEAR
Active

SHA-1 Hash

Description

Multiple npm packages in the keyv/cacheable ecosystem were compromised after attackers gained control of a GitHub maintainer account. Beginning at 9:00 UTC on August 4, 2026, the attacker introduced IDE persistence mechanisms and published malicious versions that propagated to over 400 distinct packages. The payload is a descendant of the 'Mini' Shai-Hulud malware family, sharing similarities with TeamPCP and antv campaigns. It targets sensitive data including cloud credentials, infrastructure secrets, developer credentials, AI configuration files, and cryptocurrency wallets. The malware uniquely retrieves command-and-control domains from an Ethereum smart contract rather than embedding them, allowing infrastructure updates without modifying the payload. Data is exfiltrated through GitHub repositories created under compromised identities. The campaign demonstrates sophisticated supply chain attack techniques targeting developer environments and CI/CD pipelines.

Sightings (0)

No sightings recorded yet

Details

Name / Label
npm Packages Hijacked in Supply Chain Attack
Pattern Type
STIX
Confidence
75%
Valid From
Aug 5, 2026 10:00
Total Sightings
0
Added
Aug 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 686aa40d0fc22c8d569494543a0f891f359f2f99

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.