Trendora

Keyv

Assess

Tools

A lightweight key-value storage abstraction for Node.js applications.

Why it's here

Placed in Assess: 2 article(s) of evidence from 2 source(s), led by security coverage, with 2 in the last 30 days. Confidence 37%.

Evidence (2)

  • 9The New Stack·8/7/2026security
    npm supply-chain attack hides malware behind provenance attestations

    Security researchers disclosed an npm supply-chain attack that compromised more than 400 packages, including projects tied to Keyv and Cacheable. The attackers used stolen maintainer credentials and lifecycle hooks to spread malware, showing that provenance attestations do not guarantee package integrity once a trusted workflow is compromised.

  • 9Hacker News·8/4/2026security
    Keyv and related packages hit by active Shai-Hulud npm supply-chain attack

    Several npm packages, including Keyv-related modules, were reported compromised in an active supply-chain attack dubbed Shai-Hulud. The incident highlights the risk of malicious code spreading through widely used open-source dependencies and affecting downstream projects.