‼️ The popular npm package keyv is being actively compromised (127 million weekly downloads). The attacker is still pushing malware across packages right now.
Developing story.
- The attackers of keyv also just compromised @jaredwray's cacheable repository: github.com/jaredwray/cach…The compromised packages include: keyv (127M weekly downloads) cacheable (29M/month) cache-manager (16M/month) cacheable-request (133M/month) flat-cache (565M/month) file-entry-cache (557M/month) cacheable/node-cache (5.9M/month) cacheable/memory (28M/month) cacheable/utils