Keyv
Keyv is a widely used open-source npm caching library — simple key-value storage with pluggable backends — maintained by developer Jaredwray and installed transitively by tools like ESLint. In current usage the name refers to the August 2026 npm supply-chain attack that hijacked its release pipeline.
On August 4, 2026, attackers compromised maintainer Jaredwray's GitHub account and pushed a malicious keyv@6.0.0 release carrying a preinstall hook that deployed a Mini Shai-Hulud worm payload, per Snyk. The self-propagating malware harvested npm, GitHub, and cloud credentials, ultimately touching over 400 packages with a combined 2 billion-plus monthly downloads.
Like a delivery company's warehouse getting broken into and every truck loaded with poisoned packages before anyone notices.
See nascent terms 7 days before everyone, unlock every stage filter, and get weekly early alerts.
Why is it emerging now?
A single compromised GitHub account let attackers publish a malicious keyv@6.0.0 on August 4, 2026, and the self-propagating Mini Shai-Hulud payload spread through Jaredwray's wider cacheable family into 400+ npm packages with 2 billion-plus combined monthly downloads.
Search Interest
-
Nascent ← now0–7 days
-
Emergent8–30 days
-
Validating31–90 days
-
Rising91–180 days
-
Established180 days +
Outlook
6-month signal projection and commercial timeline.
Incident coverage is dense right now but historically decays within 2-3 weeks once IOCs and patches stabilize.
Risk · If the worm resurfaces through a new poisoned maintainer account, attention could spike again rather than fade on schedule.
Analogs · Mini Shai-Hulud · xz utils backdoor · event-stream npm hijack
-
nowIncident reporting floods SERP
Dozens of vendor blogs cover IOCs, timelines, and remediation steps.
-
3-6moPostmortems and tooling reviews
Expect maintainer retrospectives and hardened-provenance tool pitches.
-
6-12moFolded into Shai-Hulud lore
Keyv becomes a cited case study, not an active search driver.
Competition & Opportunity for term “Keyv”
Signals derived from the tracked queries, the term's monetization cards, and its cluster neighbors. Heuristic except where marked measured (Google KD).
Ideas for term “Keyv”
Buildable pitches — turn this term into an article, site, product, post, newsletter, video, or course. Steal any card and run with it.
Devs are urgently searching whether their lockfiles pin a compromised version; almost no quality checklists exist yet.
Evergreen explainer covering the compromise timeline, affected package list, and safe prior versions.
Comparison piece linking this incident to the earlier worm family; near-zero competing coverage today.
CLI or GitHub Action that cross-references package-lock.json against the IOC list and opens a patch PR automatically.
Targets the exact vector this attack and Shai-Hulud both abused; whitelist-only lifecycle scripts in CI pipelines.
Recurring niche audience of security and platform engineers; Shai-Hulud variants keep recurring roughly monthly.
Two billion downloads compromised in under two hours — and the attacker didn't need a zero-day, just one stolen GitHub password.
Running npm ls turned up three of the eleven poisoned packages I didn't even know I depended on.
This malware didn't just steal your npm token — it rewrote .claude/settings.json so opening your IDE would run it again.
What People Search
Long-tail queries from Google Suggest + Trends. Volume and competition are heuristics — directional, not audited. Content Type comes from query shape.
SERP of term “Keyv”
What searchers see today — organic results on top, paid ads if anyone's bidding. Ad density is a real-time commercial signal.
FAQ
What is Keyv?
Keyv is a widely used open-source npm caching library — simple key-value storage with pluggable backends — maintained by developer Jaredwray and installed transitively by tools like ESLint.
Why is Keyv emerging now?
A single compromised GitHub account let attackers publish a malicious keyv@6.0.0 on August 4, 2026, and the self-propagating Mini Shai-Hulud payload spread through Jaredwray's wider cacheable family into 400+ npm packages with 2 billion-plus combined monthly downloads.
When did Keyv emerge?
Publicly emerged around 2026-08-04 (about 7 days ago as of 2026-08-11). EarlyTerms first recorded a pipeline signal on 2026-08-04.
Related Terms
Other terms in the same space — aliases, subtypes, competitors, and neighbors to explore next.
- Part of Mini Shai-Hulud Mini Shai-Hulud is the fourth-generation variant of the Shai-Hulud supply-chain worm family, built by threat group TeamPCP to… →
- Related Protestware Protestware is open-source software that a maintainer intentionally sabotages to deliver a political or social message, targeting users… →
- Related Dependency Cooldowns A dependency cooldown is an intentional delay between when a package version is published and when your project is allowed to install it. →
- Related Webhook Secrets A webhook secret is a shared string used to authenticate webhook deliveries: the sender computes an HMAC signature over the payload with… →
- Also known as
- Part of
- Related
Sources
Primary URLs this report cites — open any to verify the claim yourself.
- 01 Wiz — Keyv and cacheable npm Package Hijacked in Supply Chain Attack wiz.io ↗
- 02 Snyk — Inside the keyv npm Supply Chain Compromise snyk.io ↗
- 03 Socket — Popular npm Packages in the Keyv and Cacheable Namespaces Compromised socket.dev ↗
- 04 Aikido — Keyv and friends compromised in active Shai-Hulud supply chain attack aikido.dev ↗
- 05 Hacker News discussion news.ycombinator.com ↗
- 06 GitHub — jaredwray/keyv (compromised repo) github.com ↗