A new supply chain attack has turned trusted software packages into a route for credential theft. The campaign started after attackers compromised the maintainer account behind the widely used Keyv library, then exploited that access to push malicious releases across numerous projects. This incident is significant because npm packages are often automatically installed during development and build processes, making them vulnerable without users visiting suspicious websites or opening malicious attachments.
Indicators of Compromise (IoCs): - npm package keyv@6.0.0 Confirmed malicious package release - npm package file-entry-cache@11.1.6 Confirmed malicious package release - npm package cache-manager@7.2.10 Confirmed malicious package release - npm package cacheable-request@13.0.20 Confirmed malicious package release - npm package qlik/api@2.14.2 Confirmed malicious package release - npm package cacheable/memory Affected package identified in the campaign - npm package cacheable/utils Affected package identified in the campaign - npm package cacheable/net Affected package identified in the campaign - package scope servicetitan/* More than 17 affected packages, including eslint-config, anvil-themes, table, form, and log-service - malicious file setup.mjs Obfuscated dropper launched through the malicious preinstall hook - malicious file Math_Symbol.js Credential-stealing payload - malicious file Math_Init.js Credential-stealing payload Detection name: Trojan:npm/MalBun.A Microsoft Defender for Endpoint detection name Integrate real-time threat intelligence directly into your cybersecurity ecosystem using platforms like MISP, VirusTotal, or through your Security Information and Event Management (SIEM) system.












