Post by Socket on X
Socket@SocketSecurity
X🚨 Active npm supply chain attack: keyv@6.0.0 and 13 other packages have been compromised. keyv alone gets 154M weekly downloads.
The worm steals cloud and CI credentials, then uses stolen npm tokens to publish trojanized versions of more packages.

340 likes15 repliesPosted Aug 4, 2026