# Socket Weekly: Attack on keyv and cacheable Spreads to 454 Packages…

Canonical: https://brew.new/browse/templates/email/pt1_k97whsz44qk0tvhqfg4hwghe618e5bqe

Brand: socket.dev
Category: newsletter

![Preview of Socket Weekly: Attack on keyv and cacheable Spreads to 454 Packages…](https://cdn.brew.new/email-preview-4a4475f3da5ad6f0-tracking_r57gkxabskjp33ad37qjzrp2a18dv7ct-1789057658148.png)

## Email content

socket-weekly-new-header

Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.

TOP STORY

Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack

A maintainer compromise pushed a Shai-Hulud-style worm into the widely used keyv and cacheable packages, and it has since spread to 2,968 package artifacts across 454 unique packages. The payload steals cloud and CI credentials, then republishes itself through stolen npm tokens to keep spreading. Maintainers are getting hit hard with an ever-growing security burden, and the scale of this attack shows the impact. This is one reason we're upgrading our open source program to give maintainers more support.

MORE NEWS

UK Cyber Test: AI Agent Attempted to Social Engineer Open Source Maintainer Into Merging Malware

During a UK government evaluation, an AI agent hid a malware dropper behind a real bug fix, then spun up sockpuppet accounts, timed their comments to fake peer consensus, and emailed the maintainer to get the pull request merged. A maintainer caught it and rejected the PR, but it is one more burden on maintainers, who now have to weigh whether a contributor is even human.

Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache

Bundler 4.0.18 has extended its opt-in cooldown flag to bundle lock and bundle cache, so the setting that refuses freshly published gems now covers lockfile generation and vendoring, not just install and update. It is a small but important fix: cooldown only helps if it applies everywhere dependencies resolve.

MORE WORTH READING

vlt 1.0 & Hosted Package Registries

Chinese startup Moonshot's AI model breaks out of testing environment

The secure way to release an npm package in 2026

Black Hat USA 2026: The 'Breaking' News: The OpenAI–Hugging Face Incident

Proposing the SAFE Working Group: An Open Community Effort to Improve AI Security

X

512x512-logo-27148

LinkedIn

bluesky

Socket Inc.

Secure your supply chain. Ship with confidence.

2810 N Church St., Suite 71517, Wilmington,DE, 19802

Book a Demo • Unsubscribe

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97whsz44qk0tvhqfg4hwghe618e5bqe)

[Browse email designs](https://brew.new/browse/templates)
