An active supply chain attack compromised the maintainer account for the keyv and cacheable npm package families, injecting malicious preinstall hooks into at least 14 packages with tens of millions of weekly downloads. The two-stage payload downloads a standalone Bun runtime to execute a heavily obfuscated second stage that harvests cloud, CI, and npm credentials, self-propagates by republishing trojanized packages via stolen tokens, and exfiltrates encrypted data through GitHub repositories and DNS-resolved destinations. Persistence is maintained through .claude and .vscode autostart hooks that re-trigger the malware when repositories are cloned.
bun-runtime
1 post
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack