Embedded Malicious Code Affecting keyv package, versions =6.0.0


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Attacked

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-KEYV-18515941
  • published4 Aug 2026
  • disclosed3 Aug 2026
  • creditUnknown

Introduced: 3 Aug 2026

New Malicious CVE NOT AVAILABLE CWE-506  (opens in a new tab)

How to fix?

Avoid using all malicious instances of the keyv package.

Overview

Affected versions of this package are vulnerable to Embedded Malicious Code. This package was involved in a supply chain compromise that affected multiple namespaces on the npm registry, including popular caching and key-value storage utilities. A malicious actor compromised a maintainer’s account or CI pipeline, allowing them to publish tampered versions across dozens of packages. The payload subsequently acted as a self-propagating worm by harvesting developer tokens from compromised environments and republishing new infected packages across other organizations.

Malware Behavior

The compromised packages contain an obfuscated dropper script (setup.mjs) that silently downloads the Bun JavaScript runtime to execute a secondary payload (often named Math_Symbol.js). The malware focuses on extensive credential theft, extracting AWS, GCP, Azure, npm, HashiCorp Vault, and Kubernetes secrets, and can scrape GitHub Actions runner memory. Furthermore, it appears to install a dead-man's switch designed to execute additional attacker-controlled commands as soon as the stolen GitHub token is revoked. Data is exfiltrated securely using encrypted GitHub Actions artifacts and dead-drop repositories, meaning no malicious C2 domains will appear in standard network logs.

Notes

  • The worm aggressively propagated to multiple namespaces within minutes by utilizing the stolen tokens of infected users and continues to spread.
  • In keyv, which appears to be one of the earlier compromises, the threat actor also committed malicious configuration files (.vscode/tasks.json and .claude/settings.json) directly to the public repository, which triggers the malware if a developer simply clones and opens the project in VS Code or Claude Code.
  • While many affected packages have been flagged, latest tags might still resolve to poisoned versions or linger in developer lockfiles, making immediate dependency auditing critical.

CVSS Base Scores

version 4.0
version 3.1