EarlyTerms

Keyv

Nascent · Emerged · 7 days old · Last reviewed
Search / mo
~4.6K /mo
Competition KD
Stage
Nascent
measured 2026-08-05 sources · 6

Keyv is a widely used open-source npm caching library — simple key-value storage with pluggable backends — maintained by developer Jaredwray and installed transitively by tools like ESLint. In current usage the name refers to the August 2026 npm supply-chain attack that hijacked its release pipeline.

On August 4, 2026, attackers compromised maintainer Jaredwray's GitHub account and pushed a malicious keyv@6.0.0 release carrying a preinstall hook that deployed a Mini Shai-Hulud worm payload, per Snyk. The self-propagating malware harvested npm, GitHub, and cloud credentials, ultimately touching over 400 packages with a combined 2 billion-plus monthly downloads.

Like a delivery company's warehouse getting broken into and every truck loaded with poisoned packages before anyone notices.

EarlyTerms Pro

See nascent terms 7 days before everyone, unlock every stage filter, and get weekly early alerts.

Why is it emerging now?

TL;DR

A single compromised GitHub account let attackers publish a malicious keyv@6.0.0 on August 4, 2026, and the self-propagating Mini Shai-Hulud payload spread through Jaredwray's wider cacheable family into 400+ npm packages with 2 billion-plus combined monthly downloads.

5 forces driving coverage — scroll →

Search Interest

peak ~4.6K/mo
updated 2026-08-05
~4.6K/mo ~2.3K/mo 0
2026-07-07 2026-07-22 2026-08-05
Term Lifecycle
  1. Nascent ← now
    0–7 days
  2. Emergent
    8–30 days
  3. Validating
    31–90 days
  4. Rising
    91–180 days
  5. Established
    180 days +

Outlook

6-month signal projection and commercial timeline.

Signal medium
Revenue moderate

Incident coverage is dense right now but historically decays within 2-3 weeks once IOCs and patches stabilize.

Risk · If the worm resurfaces through a new poisoned maintainer account, attention could spike again rather than fade on schedule.

Analogs · Mini Shai-Hulud · xz utils backdoor · event-stream npm hijack

Monetization timeline
  1. now
    Incident reporting floods SERP

    Dozens of vendor blogs cover IOCs, timelines, and remediation steps.

  2. 3-6mo
    Postmortems and tooling reviews

    Expect maintainer retrospectives and hardened-provenance tool pitches.

  3. 6-12mo
    Folded into Shai-Hulud lore

    Keyv becomes a cited case study, not an active search driver.

Competition & Opportunity for term “Keyv”

Signals derived from the tracked queries, the term's monetization cards, and its cluster neighbors. Heuristic except where marked measured (Google KD).

Content Gap
10 queries tracked
Led by General (10)
10 Suggest-only tails — long-tail opening
Revenue Potential
0% commercial-intent queries
2 monetization angles mapped
Mostly informational — pre-commercial
Build Difficulty
Low (heuristic)
Stage: nascent — blue-ocean timing
7 / 13 default TLDs taken · oldest incumbent keyv.com (2002-01-14)
4 related terms already published
Heuristic · signals: tracked queries, term monetization cards, cluster neighbors

Ideas for term “Keyv”

Buildable pitches — turn this term into an article, site, product, post, newsletter, video, or course. Steal any card and run with it.

Article
Am I Affected by the Keyv npm Attack? A Package-by-Package Checklist

Devs are urgently searching whether their lockfiles pin a compromised version; almost no quality checklists exist yet.

Article
Keyv npm Supply-Chain Attack, Explained: Timeline, IOCs, and What to Patch

Evergreen explainer covering the compromise timeline, affected package list, and safe prior versions.

Article
Mini Shai-Hulud vs the Original Shai-Hulud: How the npm Worm Evolved

Comparison piece linking this incident to the earlier worm family; near-zero competing coverage today.

Product
Lockfile scanner that flags any dependency pinned to a known-compromised Keyv/Cacheable version

CLI or GitHub Action that cross-references package-lock.json against the IOC list and opens a patch PR automatically.

Product
CI guard that blocks preinstall/postinstall lifecycle scripts by default

Targets the exact vector this attack and Shai-Hulud both abused; whitelist-only lifecycle scripts in CI pipelines.

Newsletter
A weekly 'npm Supply-Chain Watch' briefing tracking new compromised packages

Recurring niche audience of security and platform engineers; Shai-Hulud variants keep recurring roughly monthly.

Post HN / r/netsec / security Twitter
The npm Ecosystem Just Failed Its Third Supply-Chain Stress Test This Year

Two billion downloads compromised in under two hours — and the attacker didn't need a zero-day, just one stolen GitHub password.

Post Newsletter / LinkedIn
I Audited My Node Project After the Keyv Hack. Here's Every Compromised Package I Found

Running npm ls turned up three of the eleven poisoned packages I didn't even know I depended on.

Post YouTube / Tech media
Why Claude Code and VS Code Became the New Supply-Chain Attack Surface

This malware didn't just steal your npm token — it rewrote .claude/settings.json so opening your IDE would run it again.

What People Search

Long-tail queries from Google Suggest + Trends. Volume and competition are heuristics — directional, not audited. Content Type comes from query shape.

Keyword
Competition
Content Type
keyveatz
Very Low
General
keyvitup
Very Low
General
keyveats
Very Low
General
keyveatz kpop
Very Low
General
keyvello
Very Low
General
keyveatz profile
Very Low
General
keyviz
Very Low
General
keyvault
Very Low
General
1–8 of 10
1 / 2
Updated 2026-08-05 · sources: Google Trends, Google Suggest · Competition is heuristic

SERP of term “Keyv”

What searchers see today — organic results on top, paid ads if anyone's bidding. Ad density is a real-time commercial signal.

FAQ

What is Keyv?

Keyv is a widely used open-source npm caching library — simple key-value storage with pluggable backends — maintained by developer Jaredwray and installed transitively by tools like ESLint.

Why is Keyv emerging now?

A single compromised GitHub account let attackers publish a malicious keyv@6.0.0 on August 4, 2026, and the self-propagating Mini Shai-Hulud payload spread through Jaredwray's wider cacheable family into 400+ npm packages with 2 billion-plus combined monthly downloads.

When did Keyv emerge?

Publicly emerged around 2026-08-04 (about 7 days ago as of 2026-08-11). EarlyTerms first recorded a pipeline signal on 2026-08-04.

Related Terms

Other terms in the same space — aliases, subtypes, competitors, and neighbors to explore next.

Explore next
Also mentioned
  • Also known as Cacheable
  • Part of npm supply chain attack
  • Related Shai-Hulud worm·preinstall script malware·trusted publishing

Sources

Primary URLs this report cites — open any to verify the claim yourself.

  1. 01 Wiz — Keyv and cacheable npm Package Hijacked in Supply Chain Attack wiz.io
  2. 02 Snyk — Inside the keyv npm Supply Chain Compromise snyk.io
  3. 03 Socket — Popular npm Packages in the Keyv and Cacheable Namespaces Compromised socket.dev
  4. 04 Aikido — Keyv and friends compromised in active Shai-Hulud supply chain attack aikido.dev
  5. 05 Hacker News discussion news.ycombinator.com
  6. 06 GitHub — jaredwray/keyv (compromised repo) github.com
Opportunity radar
More terms breaking out right now
View →