Inside the keyv npm Compromise: preinstall Malware, Trusted Provenance, and IDE Hooks
Eleven malicious keyv npm releases exploited preinstall hooks and forged provenance attestations to deliver install-time malware — a supply-chain vector that challenges current trust-model assumptions for JavaScript ecosystems.
Summary written by editorial AI · Source link below
keyv 6.0.0 and ten related npm releases shipped install-time malware. See affected versions, hashes, detection steps, and safe remediation order.
Editorial Analysis
Supply-chain attacks exploiting package manager trust mechanisms are growing more sophisticated; European enterprises with Node.js workloads face direct exposure through transitive dependencies.
Immediately audit all projects for affected keyv versions, enforce npm install script restrictions in CI, and adopt SBOM-based provenance validation.
A widely-used npm library was weaponised with install-time malware, underscoring supply-chain risk across JavaScript-dependent enterprise applications.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Snyk Blog in a new tab.
More from the DevSecOps Desk
- Boundary-Mutation Testing for Pattern-Based Secret Detection: A Rule-Level Method and Cross-Scanner Evaluation4d
- PatchBench: Evaluating AI Agents for Vulnerability Patching4d
- Coder's registry infrastructure compromised to push malicious modules4d
- Modelstamp: Pre-Deserialization Verification of Machine-Learning Artifacts and Runtime Environment State5d
- Barriers to Using Static Application Security Testing (SAST) Tools: A Literature Review5d