• About Us
  • Contact us
  • DMCA
  • Home
  • Privacy Policy
  • Subscribe to our Newsletter
Thursday, August 6, 2026
No Result
View All Result
NEWSLETTER
The San Francisco Tribune
  • Home
  • Art
  • Business
  • Entertainment
  • Sports
  • Food
  • Magazine
  • Podcasts
  • Politics
  • Tech
  • Wellness
  • Home
  • Art
  • Business
  • Entertainment
  • Sports
  • Food
  • Magazine
  • Podcasts
  • Politics
  • Tech
  • Wellness
No Result
View All Result
The San Francisco Tribune
No Result
View All Result
Home Business

Upwind Security Reveals How One Poisoned Package Put a Third of the JavaScript World at Risk

by Editorial
August 4, 2026
in Business
0
Amiram Shachar
Share on FacebookShare on Twitter

Certain numbers explain a security incident more effectively than any description of the malware involved. keyv pulls roughly 154 million weekly downloads. When Upwind Security became the first to report a malicious release of that package, the technical mechanics became almost secondary to the arithmetic.

A compromise at that scale is not a targeted operation. It is a wide net cast across a substantial portion of the JavaScript ecosystem, and the operator does not need to know who gets caught.

Why Foundational Packages Behave Differently

Very few engineering teams install keyv deliberately. It arrives underneath something else, resolved automatically as a transitive dependency of a framework, a build tool, or a linting configuration. The developer who triggers the install has frequently never read the package name.

That structure converts a single poisoned release into an ecosystem event. Adoption decisions do not gate exposure. Dependency resolution does.

Upwind’s Combined Incident Report reflects that severity in its scoring, placing impact at 93 and the overall rating at 92, with the classification set to malicious. Upwind identifies the primary targets as Node.js developers and CI/CD systems installing any of the compromised caching packages, with downstream exposure reaching ESLint users along with any project depending on keyv, flat-cache, or cache-manager.

The Full Affected Set

The compromise extended well past the initial package. Upwind documented eight releases carrying identical payloads. Grouped by namespace, they break down as follows.

Within the @cacheable scope: @cacheable/node-cache@3.1.2, @cacheable/utils@2.5.1, and @cacheable/memory@2.2.1. Under unscoped names: keyv@6.0.0, cacheable@2.5.1, file-entry-cache@11.1.6, cache-manager@7.2.10, and flat-cache@6.1.24.

Eight simultaneous publications across multiple maintainer namespaces raises an obvious question about how the access was obtained. Upwind’s report treats the breadth as evidence of “either a coordinated multi-account compromise or a single threat actor with access to the @cacheable, keyv, and related ecosystems.”

Both readings carry consequences for defenders. Neither is a scenario that per-package trust evaluation addresses.

The Delivery Mechanism

Every affected release shares the same execution chain. A preinstall lifecycle hook fires during installation. It runs an obfuscated loader, sized at roughly 30KB in Upwind’s assessment, which pulls the Bun runtime from GitHub Releases and uses it to execute a 728KB bundled payload.

The collection scope covers AWS credentials, GitHub tokens, npm registry credentials, and HashiCorp Vault tokens, drawn from workstations and continuous integration runners alike.

Three indicators identify an affected install: the files setup.mjs and Math_Symbol.js, and the manifest command node setup.mjs.

A Parallel Campaign

Upwind separately documented a second npm compromise using the same underlying approach, this time against the Qlik and nebula.js ecosystem. Eight packages were affected: @nebula.js/sn-line-chart@2.7.1, @qlik/sdk@0.28.1, @nebula.js/stardust@7.1.2, @nebula.js/cli@7.1.2, @qlik/browserslist-config@3.0.2, @nebula.js/cli-build@7.1.2, @nebula.js/cli-serve@7.1.2, and @nebula.js/cli-sense@7.1.2.

That report scores higher still, at 94 overall with impact at 95 and evidence at 97. The mechanics track closely. A preinstall hook fires setup.mjs, which fingerprints host operating system and architecture, downloads Bun v1.3.13 from GitHub when absent, and executes a bundled 727KB payload named math_init.js with full user-level filesystem and network access.

Upwind’s read on the scope of access is direct. The breadth of affected packages, spanning CLI tools, an SDK, visualization libraries, and a browserslist config, “suggests the attacker had write access to the entire Qlik/nebula.js npm organization.”

The Concentration Problem

Two campaigns, sixteen packages, one delivery pattern. What links them is a shared assumption about how JavaScript projects build: that install-time code execution is normal, that transitive dependencies are trustworthy by default, and that a patch version bump is a routine event.

The npm ecosystem concentrates enormous downstream weight into a small number of low-level utilities. keyv is the clearest illustration at 154 million weekly downloads. Upwind’s guidance for teams that may have installed an affected version reflects the stakes: remove the compromised release, pin to a verified clean version, rotate credentials, and review CI/CD pipelines, lockfiles, and SBOMs for the affected release.

Tags: keyvnpm supply chainUpwind
Editorial

Editorial

Next Post
aerial view of city

Designing Smarter Cities: What Happens When Planners Start Understanding in 3D?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Home
  • About Us
  • Contact us
  • DMCA
  • Privacy Policy
  • Subscribe to our Newsletter

© 2026 The San Francisco Tribune. All rights reserved.

No Result
View All Result
  • Home
  • Art
  • Business
  • Entertainment
  • Sports
  • Food
  • Magazine
  • Podcasts
  • Politics
  • Tech
  • Wellness

© 2026 The San Francisco Tribune. All rights reserved.