By clicking “Accept”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.
18px_cookie
e-remove
Blog

NPM Malware Compromises keyv and cacheable with 500M+ Weekly Downloads and Spreads to Hundreds of Packages

NPM malware is spreading through some of the registry's most-downloaded packages. On August 4, 2026, malicious versions of keyv, flat-cache, and file-entry-cache, which together exceed 500 million weekly downloads, began running an install-time credential stealer. The same payload has since been republished across hundreds of other packages under multiple maintainer accounts. Endor Labs is actively tracking this campaign.

Written by
Kiran Raj
Kiran Raj
Published on
August 4, 2026
Updated on
August 4, 2026
Topics

What we know so far

Early on August 4, malicious versions appeared under the jaredwray / Cacheable ecosystem. The first wave was published through the project's legitimate GitHub Actions OIDC trusted publishing pipeline after a commit to main added a preinstall hook and two payload files. Those tarballs carry valid npm signatures and SLSA provenance.

The seed packages in that wave alone account for ~515 million weekly downloads (npm last-week API, August 4, 2026). Just three of them (keyv, flat-cache, file-entry-cache) exceed 450 million weekly downloads. Those figures sum package-level traffic and overlap in dependency trees, but they show how wide the first wave's reach is.

The campaign then spread to other maintainers' packages, typically via stolen npm publishing tokens and without provenance. As of this writing we have verified 384 packages and 1,136 malicious versions linked by a shared stage-2 payload. Treat those numbers as a floor. The list is still growing.

Affected packages

We have verified 1,136 malicious versions across 384 packages as of writing this blog post. The seed packages listed below carry the overwhelming majority of download traffic, but the full campaign spans hundreds of lower-traffic packages republished under compromised maintainer accounts. Because versions are actively being unpublished and new ones keep appearing, treat the list as a point-in-time snapshot for August 4, 2026, and as a floor rather than a final total.

  • Update 2026-08-04 11:00 PDT: Refreshed list to reflect 1,136 malicious versions across 384 packages

The complete verified list of affected package versions is embedded below.

EcosystemPackageMalicious Versions
npm@adminide-stack/clock-tik-browser12.0.24
npm@arv-bedrock/auth1.1.7, 1.1.8
npm@arv-bedrock/auth-sso1.6.2
npm@arv-bedrock/auth-sso-backend1.7.2
npm@arv-bedrock/logger1.7.2
npm@cacheable/memory2.2.1
npm@cacheable/net2.1.1
npm@cacheable/node-cache3.1.2
npm@deliveroo/determinator0.2.1
npm@deliveroo/reevent1.0.1
npm@hubsync/web-sdk-react6.3.8, 6.3.10, 6.3.12, 6.3.14, 6.3.17, 6.3.18, 6.3.20, 6.3.22, 6.3.23, 6.3.26, 6.3.29, 6.3.30, 6.3.31, 6.3.32, 6.3.33
npm@nebula.js/cli7.1.2
npm@nebula.js/cli-build7.1.2
npm@nebula.js/cli-sense7.1.2
npm@nebula.js/nucleus0.5.1
npm@nebula.js/sn-action-button2.3.1
npm@nebula.js/sn-layout-container4.4.1
npm@nebula.js/sn-line-chart2.7.1
npm@nebula.js/sn-org-chart1.7.1
npm@nebula.js/sn-shape1.5.1
npm@nebula.js/sn-slider0.20.1
npm@nebula.js/sn-tabbed-container2.4.1
npm@nebula.js/snapshooter0.6.1
npm@nebula.js/theme0.6.1
npm@onereach/bandwidth-steps-voice-bxml0.1.1, 0.1.2
npm@onereach/billing-dto27.2.2, 27.2.3
npm@onereach/billing-shared27.2.1, 27.2.2
npm@onereach/channel-transformer0.0.66, 0.0.67, 0.0.68
npm@onereach/channel-transformers0.0.5, 0.0.6, 0.0.7
npm@onereach/ckeditor5-build-classic30.0.1
npm@onereach/condition-builder1.0.8, 1.0.9, 1.0.10
npm@onereach/content-builder0.0.19
npm@onereach/expression-components9.1.2
npm@onereach/font-icons27.0.2, 27.0.3, 27.0.4
npm@onereach/get-version-data3.1.2, 3.1.3
npm@onereach/idw-apps0.1.3, 0.1.5
npm@onereach/idw-contracts0.1.3, 0.1.4
npm@onereach/idw-init-account-resources1.0.1, 1.0.2, 1.0.3
npm@onereach/idw-sdk0.1.2, 0.1.4
npm@onereach/lambda-invocation1.2.1, 1.2.2
npm@onereach/messengers-infobip-sdk0.1.1, 0.1.2
npm@onereach/or-browser0.0.48, 0.0.49
npm@onereach/or-browser-next0.0.11
npm@onereach/or-content-builder-renderer0.0.3, 0.0.4
npm@onereach/or-file-uploader-next0.0.9
npm@onereach/or-pro1.13.1, 1.13.2, 1.13.3
npm@onereach/or-sdk-agent-cli0.0.6, 0.0.7
npm@onereach/orest-cli2.4.2
npm@onereach/orest-input-cli1.18.2
npm@onereach/orest-jest-presets0.0.3
npm@onereach/orest-vue-demi-vue20.0.4, 0.0.6
npm@onereach/orest-vue-demi-vue30.0.5, 0.0.6
npm@onereach/phonenumber-interpreter0.0.20
npm@onereach/pnpm-audit-junit1.0.3
npm@onereach/regex-helper0.5.16, 0.5.17, 0.5.18
npm@onereach/regular-expressions0.5.23, 0.5.24
npm@onereach/regular-expressions-test0.0.6
npm@onereach/rwc-client6.4.7, 6.4.8, 6.4.9
npm@onereach/salesforce-miaw-client0.0.3, 0.0.4
npm@onereach/si-a-button0.0.3, 0.0.4
npm@onereach/si-alert0.4.11, 0.4.12
npm@onereach/si-checkbox0.6.6, 0.6.7
npm@onereach/si-checkbox-group0.3.5, 0.3.7
npm@onereach/si-code0.6.4, 0.6.5
npm@onereach/si-copyable-text0.4.12, 0.4.13
npm@onereach/si-datepicker0.4.6, 0.4.7
npm@onereach/si-divider0.4.12
npm@onereach/si-dropdown-advanced0.4.5
npm@onereach/si-dropdown-simple0.4.7
npm@onereach/si-header0.4.11, 0.4.12, 0.4.13
npm@onereach/si-list0.7.4
npm@onereach/si-radio-group0.3.6, 0.3.7
npm@onereach/si-root0.9.4
npm@onereach/si-select0.1.3
npm@onereach/si-step-chooser0.4.5
npm@onereach/si-switch0.4.7
npm@onereach/si-text-message0.4.5, 0.4.7
npm@onereach/si-textinput0.5.6, 0.5.7
npm@onereach/si-validated-timestring-input0.3.5, 0.3.6, 0.3.7
npm@onereach/ssml-editor2.0.12, 2.0.13, 2.0.14
npm@onereach/step-components0.1.39
npm@onereach/step-conversation1.0.41, 1.0.42
npm@onereach/step-run-snowflake-query0.1.2, 0.1.3
npm@onereach/step-voice7.0.34
npm@onereach/styles27.0.2, 27.0.3
npm@onereach/time-interpreter1.0.30, 1.0.32
npm@onereach/ts-memoize1.0.2, 1.0.3, 1.0.4
npm@onereach/types-contacts-api9.0.8
npm@onereach/ui-components27.0.3, 27.0.4
npm@onereach/ui-components-common27.0.3
npm@onereach/v-event-calendar0.1.24
npm@onereach/webform0.3.14, 0.3.15
npm@or-sdk/account-settings1.3.6, 1.3.7, 1.3.8
npm@or-sdk/accounts2.3.5, 2.3.6, 2.3.7
npm@or-sdk/adapters0.3.6, 0.3.7
npm@or-sdk/agents4.21.3, 4.21.4
npm@or-sdk/api-tokens1.4.2, 1.4.3
npm@or-sdk/api-tokens-lambda1.4.2, 1.4.3, 1.4.4
npm@or-sdk/auth0.38.1, 0.38.2, 0.38.3
npm@or-sdk/authorizer0.26.7
npm@or-sdk/base0.44.5
npm@or-sdk/billing27.2.1, 27.2.2, 27.2.3
npm@or-sdk/billing-internal27.2.1, 27.2.2
npm@or-sdk/bot-templates2.2.6, 2.2.7
npm@or-sdk/card-templates2.2.5
npm@or-sdk/cards1.2.5, 1.2.6
npm@or-sdk/ccp10.15.5, 10.15.6
npm@or-sdk/chat0.3.3
npm@or-sdk/contacts4.7.5, 4.7.6
npm@or-sdk/content-request0.2.6, 0.2.7
npm@or-sdk/data-hub0.26.6
npm@or-sdk/data-hub-svc2.3.6
npm@or-sdk/deployer1.7.5
npm@or-sdk/deployments2.1.5, 2.1.6
npm@or-sdk/discovery1.12.2
npm@or-sdk/druid1.4.9
npm@or-sdk/event-manager1.1.5, 1.1.6
npm@or-sdk/files3.11.7, 3.11.8
npm@or-sdk/files-sync-node0.1.10
npm@or-sdk/flow-templates2.1.6
npm@or-sdk/flows2.7.9, 2.7.10
npm@or-sdk/graph1.10.6
npm@or-sdk/hitl0.41.2, 0.41.3
npm@or-sdk/identifiers0.27.8
npm@or-sdk/idw-public1.6.6, 1.6.7, 1.6.8
npm@or-sdk/idw-skill1.4.1, 1.4.2, 1.4.3
npm@or-sdk/invitations1.4.9, 1.4.10
npm@or-sdk/key-value-storage0.28.6, 0.28.7
npm@or-sdk/keys1.2.6
npm@or-sdk/knowledge-models0.25.5, 0.25.7
npm@or-sdk/library0.5.6, 0.5.7
npm@or-sdk/library-categories0.2.6
npm@or-sdk/library-source0.4.5, 0.4.6
npm@or-sdk/library-types-v19.0.2, 9.0.3
npm@or-sdk/lookup1.25.1, 1.25.3
npm@or-sdk/markdowner0.5.2
npm@or-sdk/mcp-tools0.5.2, 0.5.3, 0.5.4
npm@or-sdk/notifications1.7.5, 1.7.6, 1.7.7
npm@or-sdk/password1.3.6, 1.3.7
npm@or-sdk/permissions2.8.2, 2.8.3
npm@or-sdk/permissions-cli1.4.1, 1.4.2
npm@or-sdk/permissions-lambda2.5.1, 2.5.2
npm@or-sdk/pgsql1.5.2, 1.5.3
npm@or-sdk/providers0.3.6, 0.3.8
npm@or-sdk/qna3.4.3
npm@or-sdk/queue-manager1.4.6, 1.4.7, 1.4.8
npm@or-sdk/sdk-api0.29.2, 0.29.3
npm@or-sdk/settings0.25.7
npm@or-sdk/sku-builder2.5.1, 2.5.3
npm@or-sdk/source2.1.5
npm@or-sdk/source-api1.1.1, 1.1.2
npm@or-sdk/step-templates2.2.6
npm@or-sdk/store2.1.6
npm@or-sdk/tables0.28.5, 0.28.7
npm@or-sdk/tags1.1.7
npm@or-sdk/tickets1.9.6, 1.9.7
npm@or-sdk/users3.8.2, 3.8.3
npm@or-sdk/view-templates2.2.5
npm@or-sdk/views3.1.6, 3.1.7
npm@or-sdk/web-search0.6.1, 0.6.2, 0.6.3
npm@ornikar/apollo-link-timeout1.4.2, 1.4.6, 1.4.8, 1.4.10
npm@ornikar/babel-preset-base6.0.4, 6.0.5, 6.0.8, 6.0.9, 6.0.11, 6.0.13
npm@ornikar/babel-preset-kitt-universal8.0.4
npm@ornikar/babel-preset-react6.1.4, 6.1.5, 6.1.7, 6.1.9, 6.1.12, 6.1.13
npm@ornikar/browserslist-config8.0.3, 8.0.5, 8.0.6, 8.0.7, 8.0.8, 8.0.9, 8.0.10
npm@ornikar/commitlint-config8.3.2, 8.3.4, 8.3.6, 8.3.7, 8.3.9, 8.3.10
npm@ornikar/eslint-config24.0.1, 24.0.4, 24.0.5, 24.0.6, 24.0.10, 24.0.11
npm@ornikar/eslint-config-babel24.0.5, 24.0.7, 24.0.8, 24.0.11
npm@ornikar/eslint-config-babel-use13.2.6, 13.2.7, 13.2.8, 13.2.9
npm@ornikar/eslint-config-formatjs24.0.2, 24.0.4, 24.0.5
npm@ornikar/eslint-config-node12.2.1, 12.2.3, 12.2.5, 12.2.7, 12.2.8, 12.2.10
npm@ornikar/eslint-config-react24.0.1, 24.0.3, 24.0.4, 24.0.8, 24.0.10
npm@ornikar/eslint-config-typescript24.0.3, 24.0.5, 24.0.8
npm@ornikar/eslint-config-typescript-nestjs24.0.2, 24.0.3, 24.0.4, 24.0.8, 24.0.9
npm@ornikar/eslint-config-typescript-react24.0.2, 24.0.4, 24.0.6, 24.0.7, 24.0.8, 24.0.9
npm@ornikar/eslint-plugin-neverthrow1.3.5, 1.3.7
npm@ornikar/eslint-plugin-ornikar24.0.1, 24.0.2, 24.0.4, 24.0.6, 24.0.7, 24.0.9, 24.0.10, 24.0.11
npm@ornikar/graphql-config1.1.2, 1.1.6, 1.1.7, 1.1.8, 1.1.10, 1.1.11
npm@ornikar/intl-config10.0.2, 10.0.3, 10.0.4, 10.0.6, 10.0.7
npm@ornikar/jest-config13.0.8, 13.0.9, 13.0.10, 13.0.13
npm@ornikar/jest-config-react18.0.2, 18.0.3, 18.0.4, 18.0.5, 18.0.7, 18.0.9, 18.0.11
npm@ornikar/jest-config-react-native17.0.3, 17.0.4, 17.0.5, 17.0.7, 17.0.8, 17.0.9, 17.0.10, 17.0.12
npm@ornikar/jest-config-react-native-web12.0.5, 12.0.8, 12.0.10, 12.0.12, 12.0.13
npm@ornikar/kitt21.0.3, 1.0.5, 1.0.6, 1.0.8, 1.0.9
npm@ornikar/lerna-config11.0.2, 11.0.4, 11.0.6, 11.0.8, 11.0.9, 11.0.10, 11.0.11
npm@ornikar/monorepo-config14.3.5, 14.3.6, 14.3.7, 14.3.9, 14.3.10
npm@ornikar/postcss-config9.1.6, 9.1.7, 9.1.10, 9.1.12
npm@ornikar/prettier-config9.0.3, 9.0.4, 9.0.6, 9.0.8, 9.0.9
npm@ornikar/prismic-components0.0.4, 0.0.7, 0.0.9, 0.0.10
npm@ornikar/react-modern-calendar-datepicker3.2.1, 3.2.2, 3.2.3, 3.2.4, 3.2.6, 3.2.7, 3.2.8, 3.2.9
npm@ornikar/react-native-svg-transformer1.0.7, 1.0.10, 1.0.11, 1.0.12
npm@ornikar/renovate-config9.0.3, 9.0.4, 9.0.8, 9.0.9, 9.0.10, 9.0.12
npm@ornikar/repo-config15.3.7, 15.3.8, 15.3.13
npm@ornikar/repo-config-react13.0.9, 13.0.10, 13.0.12, 13.0.14, 13.0.16, 13.0.17
npm@ornikar/repo-config-react-legacy-css15.1.3, 15.1.6, 15.1.13
npm@ornikar/rollup-config11.1.7, 11.1.8, 11.1.9, 11.1.11, 11.1.13
npm@ornikar/rollup-plugin-postcss2.0.5, 2.0.8, 2.0.9, 2.0.10, 2.0.12, 2.0.13
npm@ornikar/slate-react-fork1.0.3, 1.0.4, 1.0.5, 1.0.7, 1.0.9
npm@ornikar/storybook-config12.1.2, 12.1.8, 12.1.10
npm@ornikar/stylelint-config14.0.5, 14.0.8
npm@ornikar/typed-css-modules-loader0.8.7, 0.8.8, 0.8.12
npm@ornikar/webpack-config12.0.4, 12.0.9, 12.0.10, 12.0.11
npm@picsart/gen-ai2.55.11
npm@qlik/carbon-core2.1.1
npm@qlik/carboncopy1.1.6
npm@qlik/dts-bundler2.0.3
npm@qlik/embed-runtime1.6.4
npm@qlik/eslint-config2.0.20
npm@qlik/eslint-config-svelte0.1.1
npm@qlik/eslint-config-vue0.1.1
npm@qlik/oxfmt-config0.1.6
npm@qlik/oxlint-config0.7.2
npm@qlik/react-native-simple-grid1.5.5
npm@qlik/runtime-module-loader1.5.1
npm@qlik/sdk0.28.1
npm@qlik/sprout-design-docs1.0.2
npm@qlik/sprout-icons0.12.3
npm@qlik/sprout-react6.45.3
npm@qlik/sprout-react-table0.16.7
npm@servicetitan/acquisition-functions5.22.3, 5.22.5
npm@servicetitan/admin-layout2.4.3, 2.4.5, 2.4.6
npm@servicetitan/admin-sql-table1.0.15, 1.0.16, 1.0.17, 1.0.18, 1.0.19
npm@servicetitan/ajax-handlers38.1.1, 38.1.3, 38.1.4, 38.1.5, 38.1.7
npm@servicetitan/anvil-css-utilities14.5.5, 14.5.7, 14.5.9, 14.5.10
npm@servicetitan/anvil-fonts14.5.4, 14.5.6, 14.5.7, 14.5.8, 14.5.10
npm@servicetitan/anvil-icon0.5.1, 0.5.3
npm@servicetitan/anvil-icons14.5.5, 14.5.6, 14.5.7, 14.5.8, 14.5.9, 14.5.10
npm@servicetitan/anvil-react0.11.5, 0.11.8, 0.11.9
npm@servicetitan/anvil-themes14.5.5, 14.5.6, 14.5.8, 14.5.9
npm@servicetitan/anvil-token0.4.2, 0.4.5, 0.4.6
npm@servicetitan/anvil23.9.1, 3.9.3, 3.9.4, 3.9.5, 3.9.6
npm@servicetitan/anvil2-codemods0.11.2, 0.11.3, 0.11.6
npm@servicetitan/anvil2-ext-atlas4.0.3, 4.0.4, 4.0.5, 4.0.7
npm@servicetitan/anvil2-ext-charts0.2.4, 0.2.5, 0.2.6, 0.2.9
npm@servicetitan/anvil2-ext-common0.7.1, 0.7.6
npm@servicetitan/anvil2-ext-mwv0.0.5, 0.0.6, 0.0.7, 0.0.8, 0.0.10, 0.0.11
npm@servicetitan/anvil2-illustrations1.0.2, 1.0.4, 1.0.6, 1.0.7
npm@servicetitan/anvil2-mcp0.0.10, 0.0.11, 0.0.12, 0.0.13, 0.0.15
npm@servicetitan/assist-ui2.1.4, 2.1.7
npm@servicetitan/assist-utils1.1.2, 1.1.3, 1.1.5, 1.1.6
npm@servicetitan/carto-charts-core0.0.2, 0.0.5, 0.0.6
npm@servicetitan/carto-charts-react0.0.5, 0.0.6, 0.0.8
npm@servicetitan/carto-charts-rn0.0.5
npm@servicetitan/carto-react-kit0.8.4, 0.8.5, 0.8.7, 0.8.8, 0.8.9, 0.8.10
npm@servicetitan/carto-rn-kit0.0.11, 0.0.12, 0.0.13, 0.0.14, 0.0.15, 0.0.16
npm@servicetitan/carto-tokens0.3.1, 0.3.2, 0.3.4, 0.3.5
npm@servicetitan/confirm41.3.1, 41.3.4, 41.3.5
npm@servicetitan/confirm-navigation41.3.1, 41.3.2, 41.3.3, 41.3.5, 41.3.6, 41.3.7
npm@servicetitan/contentful0.0.4, 0.0.6, 0.0.8
npm@servicetitan/contentful-proxy1.1.12, 1.1.14, 1.1.15, 1.1.16, 1.1.17
npm@servicetitan/cp-api1.115.1, 1.115.5, 1.115.6
npm@servicetitan/cp-mfe1.115.4, 1.115.6
npm@servicetitan/cp-mfe-dev1.115.2, 1.115.4, 1.115.5, 1.115.7
npm@servicetitan/cp-react-hooks1.115.1, 1.115.2, 1.115.3, 1.115.4, 1.115.5, 1.115.7
npm@servicetitan/cp-ui1.115.2, 1.115.4, 1.115.5, 1.115.6, 1.115.7
npm@servicetitan/culture41.3.1, 41.3.2, 41.3.3, 41.3.6, 41.3.7
npm@servicetitan/data-query41.3.1, 41.3.5
npm@servicetitan/datadog-rum38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
npm@servicetitan/datetime-utils41.3.2, 41.3.3, 41.3.5, 41.3.7
npm@servicetitan/design-system14.5.10
npm@servicetitan/docs-anvil-uikit-contrib41.3.2, 41.3.4, 41.3.5, 41.3.6, 41.3.7
npm@servicetitan/docs-uikit38.1.1, 38.1.2, 38.1.5, 38.1.6, 38.1.7
npm@servicetitan/document-title2.4.3, 2.4.4, 2.4.5
npm@servicetitan/dte-pdf-editor1.76.1, 1.76.2, 1.76.4
npm@servicetitan/dte-unlayer0.150.4, 0.150.5, 0.150.7
npm@servicetitan/eh-module-communication0.2.1, 0.2.2, 0.2.4, 0.2.5, 0.2.7
npm@servicetitan/error-boundary38.1.1, 38.1.2, 38.1.4, 38.1.5, 38.1.6, 38.1.7
npm@servicetitan/eslint-config38.1.2, 38.1.7
npm@servicetitan/eslint-plugin38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.6
npm@servicetitan/eslint-plugin-decorators-declare12.8.15, 12.8.18
npm@servicetitan/eslint-plugin-folder-schema38.1.2, 38.1.3, 38.1.6, 38.1.7
npm@servicetitan/eslint-plugin-mobx-612.8.15, 12.8.16
npm@servicetitan/eslint-plugin-processors-stub12.8.15, 12.8.17, 12.8.21
npm@servicetitan/examples1.2.7, 1.2.9, 1.2.11
npm@servicetitan/feature-spotlight3.9.1, 3.9.2, 3.9.3, 3.9.4, 3.9.5, 3.9.7
npm@servicetitan/folder-lint38.1.3, 38.1.4, 38.1.6
npm@servicetitan/forge0.5.7
npm@servicetitan/form41.3.2, 41.3.6, 41.3.7
npm@servicetitan/form-state41.3.5, 41.3.7
npm@servicetitan/grid0.0.63, 0.0.69
npm@servicetitan/hammer-icon1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7
npm@servicetitan/hammer-react1.42.5, 1.42.7
npm@servicetitan/hammer-token3.1.6
npm@servicetitan/hash-browser-router38.1.1, 38.1.4, 38.1.5, 38.1.6
npm@servicetitan/help-center1.0.8, 1.0.11, 1.0.12, 1.0.13
npm@servicetitan/html-sketchapp4.2.12
npm@servicetitan/install38.1.2, 38.1.7
npm@servicetitan/intl7.2.6, 7.2.7
npm@servicetitan/json-render-react0.4.8, 0.4.9, 0.4.10, 0.4.11, 0.4.12
npm@servicetitan/kendo-theme0.0.27, 0.0.28, 0.0.29, 0.0.30
npm@servicetitan/ko-bridge38.1.2, 38.1.3, 38.1.4, 38.1.7
npm@servicetitan/launchdarkly-service38.1.1, 38.1.4
npm@servicetitan/lazy-module38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.7
npm@servicetitan/ld-type-generator0.2.2, 0.2.3, 0.2.4, 0.2.5, 0.2.7
npm@servicetitan/line-item-editor1.5.3, 1.5.5, 1.5.7
npm@servicetitan/link-item41.3.1, 41.3.4, 41.3.5, 41.3.6, 41.3.7
npm@servicetitan/log-service38.1.1, 38.1.2, 38.1.3, 38.1.4
npm@servicetitan/marketing-direct-mail-components20.1.4, 20.1.6, 20.1.7
npm@servicetitan/marketing-form0.1.2, 0.1.3, 0.1.4, 0.1.5, 0.1.7
npm@servicetitan/marketing-global-route1.14.2, 1.14.3, 1.14.4, 1.14.5, 1.14.7
npm@servicetitan/marketing-integration-widgets1.0.40, 1.0.42, 1.0.43, 1.0.44, 1.0.45
npm@servicetitan/marketing-route1.2.1, 1.2.2, 1.2.3, 1.2.4
npm@servicetitan/marketing-ui9.3.1, 9.3.2, 9.3.5
npm@servicetitan/marketing-widgets1.0.1, 1.0.4, 1.0.5
npm@servicetitan/measure-sheet-data2.6.1, 2.6.2, 2.6.4, 2.6.5, 2.6.6
npm@servicetitan/mfe-quick-actions0.5.50, 0.5.52, 0.5.53, 0.5.54
npm@servicetitan/micro-frontend0.0.5, 0.0.6, 0.0.7, 0.0.8, 0.0.9, 0.0.10
npm@servicetitan/microfront0.0.4, 0.0.5, 0.0.6
npm@servicetitan/microfront-auth0.0.7, 0.0.8, 0.0.9, 0.0.10
npm@servicetitan/microfront-tests0.0.11, 0.0.13, 0.0.15, 0.0.16
npm@servicetitan/microfront-utils1.4.2, 1.4.4, 1.4.7
npm@servicetitan/modularpayments-webfields1.0.53, 1.0.54, 1.0.57
npm@servicetitan/moneyout-api-client1.29.1, 1.29.2, 1.29.3, 1.29.5, 1.29.6
npm@servicetitan/mpa-components2.5.2, 2.5.3, 2.5.5
npm@servicetitan/navigation14.1.1
npm@servicetitan/notifications41.3.4, 41.3.5
npm@servicetitan/onboarding-ui18.5.2, 18.5.5, 18.5.6, 18.5.7
npm@servicetitan/quick-actions1.15.3, 1.15.4, 1.15.6, 1.15.7
npm@servicetitan/react-hooks7.7.1, 7.7.2, 7.7.4, 7.7.7
npm@servicetitan/react-ioc38.1.4
npm@servicetitan/responsive6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7
npm@servicetitan/restrict-imports38.1.1, 38.1.2, 38.1.3
npm@servicetitan/schema-comparison0.1.3, 0.1.5, 0.1.6, 0.1.9
npm@servicetitan/skeleton9.2.4, 9.2.5, 9.2.6, 9.2.7, 9.2.8
npm@servicetitan/standalone-core-feature-gates1.11.5, 1.11.6, 1.11.7, 1.11.8, 1.11.10
npm@servicetitan/standalone-feature-flags2.3.2, 2.3.3, 2.3.4, 2.3.5, 2.3.6
npm@servicetitan/standalone-root1.11.3, 1.11.4, 1.11.5, 1.11.7, 1.11.9
npm@servicetitan/standalone-tm-api1.1.1, 1.1.2, 1.1.5
npm@servicetitan/standalone-ui2.2.9
npm@servicetitan/startup38.1.5, 38.1.6, 38.1.7
npm@servicetitan/startup-jest2.2.1, 2.2.3, 2.2.4, 2.2.5, 2.2.7
npm@servicetitan/startup-mfe-compat0.5.1, 0.5.2, 0.5.5, 0.5.6
npm@servicetitan/startup-utils38.1.2, 38.1.3, 38.1.4, 38.1.5
npm@servicetitan/stylelint-config38.1.2, 38.1.3, 38.1.5
npm@servicetitan/suppress-warnings38.1.1, 38.1.2, 38.1.5
npm@servicetitan/table41.3.2, 41.3.3, 41.3.4, 41.3.5, 41.3.6
npm@servicetitan/tanstack-query-mobx6.2.2, 6.2.4, 6.2.6, 6.2.7
npm@servicetitan/temporal-lite3.4.4, 3.4.5, 3.4.6
npm@servicetitan/testing-library6.6.2
npm@servicetitan/thoughtspot-theme1.7.1, 1.7.4, 1.7.7
npm@servicetitan/time-zones3.8.1, 3.8.3, 3.8.6, 3.8.7
npm@servicetitan/titan-chat-ui7.1.3, 7.1.7, 7.1.8, 7.1.9
npm@servicetitan/titan-chat-ui-anvil29.0.2, 9.0.5, 9.0.7
npm@servicetitan/titan-chat-ui-common9.0.3, 9.0.7
npm@servicetitan/titan-chat-ui-cypress2.1.4, 2.1.5, 2.1.6, 2.1.7, 2.1.9
npm@servicetitan/titan-chatbot-api9.0.1, 9.0.3, 9.0.4
npm@servicetitan/titan-chatbot-client2.1.4, 2.1.5, 2.1.8
npm@servicetitan/titan-chatbot-ui7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.9
npm@servicetitan/titan-chatbot-ui-anvil29.0.5, 9.0.6
npm@servicetitan/titan-chatbot-ui-cypress9.0.1, 9.0.2, 9.0.4, 9.0.5
npm@servicetitan/tokens12.9.1, 12.9.4, 12.9.7
npm@servicetitan/toolbelt-shared-registry1.14.1, 1.14.2, 1.14.6
npm@servicetitan/uikit-docs22.11.1, 22.11.2, 22.11.5, 22.11.7
npm@servicetitan/unit-tests0.0.2, 0.0.3, 0.0.4, 0.0.5, 0.0.6, 0.0.7, 0.0.8
npm@servicetitan/va-mfe-loader1.1.2, 1.1.4, 1.1.7
npm@servicetitan/web-components38.1.1, 38.1.5
npm@servicetitan/widget-platform5.6.1, 5.6.2, 5.6.3, 5.6.4, 5.6.6, 5.6.7
npm@servicetitan/widget-platform-monolith5.6.4, 5.6.5, 5.6.7
npm@umacloud/cli-linux-musl-arm641.0.74
npm@umacloud/cli-linux-x641.0.74
npmbabel-plugin-linaria-css-to-undefined0.3.1, 0.3.2, 0.3.4, 0.3.6, 0.3.8, 0.3.9, 0.3.11, 0.3.13, 0.3.14, 0.3.16, 0.3.17
npmcache-manager7.2.10
npmcacheable2.5.1
npmconv-context-next1.0.1, 1.0.2, 1.0.3, 1.0.7, 1.0.9, 1.0.10
npmeditable-contracts0.0.12, 0.0.13, 0.0.15, 0.0.17, 0.0.21, 0.0.22, 0.0.24
npmeslint-plugin-folder-schema1.0.6, 1.0.8, 1.0.10, 1.0.12, 1.0.13, 1.0.14, 1.0.16, 1.0.19, 1.0.21
npmexample-js-project1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.9, 1.0.10, 1.0.11
npmfile-entry-cache11.1.6
npmfolder-lint1.0.7, 1.0.10, 1.0.11, 1.0.13, 1.0.16, 1.0.20, 1.0.21
npmfrontend-orb4.4.1, 4.4.3, 4.4.5, 4.4.7, 4.4.8, 4.4.9, 4.4.10, 4.4.12, 4.4.14, 4.4.18
npmkeyv6.0.0
npmnative-frontend-orb1.1.7, 1.1.8, 1.1.9, 1.1.13, 1.1.14, 1.1.15
npmpicasso-plugin-q2.11.6
npmpob-test-package-in-monorepo5.2.3, 5.2.6, 5.2.7, 5.2.8, 5.2.9, 5.2.12, 5.2.13
npmpob-test-typescript-package-in-monorepo4.2.1, 4.2.9, 4.2.11
npmqlik-modifiers0.10.1
npmqlik-object-conversion0.17.2
npmrwc-client0.29.10, 0.29.11, 0.29.12, 0.29.15, 0.29.17, 0.29.19
npmserver-hemera-mongo0.0.12
npmtslint-folder-schema1.0.6, 1.0.7, 1.0.10, 1.0.11, 1.0.13, 1.0.14, 1.0.16, 1.0.21
npmumadev1.0.74
npmverdaccio-okta-oauth38.1.1, 38.1.2, 38.1.3, 38.1.5, 38.1.7, 38.1.8, 38.1.10, 38.1.11, 38.1.16
npmverdaccio-tarball-local-storage38.1.2, 38.1.3, 38.1.4, 38.1.6, 38.1.8
npmworkbench-browser-server0.0.2

Highest-impact seed packages

These packages drive most real-world exposure. flat-cache and file-entry-cache sit in the ESLint dependency chain, so many projects pull them in transitively (often as dev dependencies only). That does not reduce risk: the malware runs on npm install.

Weekly downloads from the npm downloads API (last-week, as of August 4, 2026):

PackageMalicious versionWeekly downloads
keyv6.0.0154,055,938
flat-cache6.1.24149,868,983
file-entry-cache11.1.6147,558,494
cacheable-request13.0.2033,963,726
@cacheable/utils2.5.18,713,375
cacheable2.5.17,877,004
@cacheable/memory2.2.17,176,667
cache-manager7.2.104,281,731
@cacheable/node-cache3.1.21,555,151
@cacheable/net2.1.1975
ecto5.0.11,293
Seed total~515,000,000

Several of these versions have already been unpublished. Do not treat "latest looks clean" as proof you never installed a bad version. Check lockfiles and CI logs.

Spread beyond the seed wave

After the initial Cacheable / jaredwray wave, the same payload was republished under multiple unrelated maintainer accounts, including several belonging to established software organizations. The pattern is consistent across them: an npm publishing token was stolen and used to push malicious versions, in most cases a CI or service-account token likely harvested from a build runner that had itself installed a poisoned dependency.

Notably, some of the malicious versions were published under the npm scopes of legitimate, well-known software companies, using their own maintainer or CI credentials. Verified examples include @servicetitan/* (ServiceTitan), @ornikar/* (Ornikar), @onereach/* and @or-sdk/* (OneReach), @qlik/* and @nebula.js/* (Qlik), @hubsync/* (HubSync), @picsart/* (Picsart), @arv-bedrock/* (Bedrock Analytics), and @adminide-stack/* (CDMBase). In each case the scope was abused through a stolen publishing token, not through any compromise of the company's own systems, and the packages have been reported to npm and the affected maintainers.

Attack chain (summary)

Every confirmed malicious version adds:

"scripts": {
  "preinstall": "node setup.mjs"
}

setup.mjs is an obfuscated dropper. It downloads a unmodified Bun 1.3.13 binary from official GitHub releases, then uses Bun to execute a ~727 KB obfuscated stage-2 payload shipped in the package (Math_Symbol.js in the first wave, math_init.js later). The two filenames are byte-identical.

Using Bun means the malware brings its own runtime and does not need a malicious download domain for the executor. The only network fetch in stage 1 is a legitimate Bun release.

Intial analysis of the payload confirms targeting of AWS credentials, npm tokens, GitHub tokens (including ghs_ Actions / App tokens), and HashiCorp Vault tokens. The bundle also includes packaging and npm publish machinery that matches the self-propagation we observed across maintainer accounts.

Indicators of compromise

TypeValue
Stage-2 payload SHA-2569fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc
Stage-2 filenamesMath_Symbol.js, math_init.js (727,680 bytes, byte-identical)
Wave-1 dropper SHA-25654dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668 (setup.mjs)
Later-wave dropper SHA-256fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb (setup.mjs)
Lifecycle hook"preinstall": "node setup.mjs"
BehavioralBun binary downloaded or executed during npm install; bun-dl-* temp directories

What to do now

  1. Pin or roll back affected packages to versions published before 2026-08-04 09:30 UTC.
  2. Use npm/yarn/pnpm overrides for keyv, flat-cache, and file-entry-cache. They are usually transitive.
  3. Search lockfiles and CI logs for malicious versions, including devDependencies.
  4. Rotate credentials on any machine or runner that ran npm install after 09:30 UTC: npm tokens, GitHub PATs, cloud keys, CI secrets, Vault tokens.
  5. Prefer --ignore-scripts in CI. It blocks this class of install-hook malware.

We are tracking this

Endor Labs is verifying new publishes, updating affected-package coverage as versions appear, and preparing a full technical write-up of the loader, worming behavior, and infra. This is an initial advisory while the campaign is ongoing. We will expand with in-depth technical analysis in a follow-up post.

Description goes here