Keyv
AssessTools
A lightweight key-value storage abstraction for Node.js applications.
Why it's here
Placed in Assess: 2 article(s) of evidence from 2 source(s), led by security coverage, with 2 in the last 30 days. Confidence 37%.
Evidence (2)
- 9The New Stack·8/7/2026securitynpm supply-chain attack hides malware behind provenance attestations
Security researchers disclosed an npm supply-chain attack that compromised more than 400 packages, including projects tied to Keyv and Cacheable. The attackers used stolen maintainer credentials and lifecycle hooks to spread malware, showing that provenance attestations do not guarantee package integrity once a trusted workflow is compromised.
- 9Hacker News·8/4/2026securityKeyv and related packages hit by active Shai-Hulud npm supply-chain attack
Several npm packages, including Keyv-related modules, were reported compromised in an active supply-chain attack dubbed Shai-Hulud. The incident highlights the risk of malicious code spreading through widely used open-source dependencies and affecting downstream projects.