keyv/cacheable npm Package Hijacked Supply Chain Attack
A GitHub maintainer account related to the keyv/cacheable npm package ecosystem was compromised. The attacker published malicious versions of these packages, which affected more than 400 npm packages. The malware is designed to steal cloud credentials, developer secrets, CI/CD secrets, AI tool configuration files, and cryptocurrency wallet data. It also creates persistence using Claude Code hooks and VS Code tasks.json files, and sends stolen data to attacker-controlled GitHub repositories and C2 domains. Reference article: https://www.wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack
Microsoft Sentinel (KQL)

