Keyv

The npm Setting Nobody’s Talking About That Stops Supply Chain Attacks

The Keyv/Cacheable npm worm compromised over 350 packages by exploiting our trust in popular packages. The fix isn’t better detectionโ€”it’s a single line in .npmrc: min-release-age=30. This simple time delay blocks opportunistic supply-chain attacks because attackers can’t afford to wait weeks for their malware to spread. Add it now.

The 127 Million Weekly Download Nobody’s Talking About

Keyv, an npm package with 127 million weekly downloads that most developers never directly install, was compromised via a stolen credential. The real vulnerability isn’t the codeโ€”it’s the economic model of open source, where unpaid maintainers silently hold up the internet’s dependency tree, and trust is mistaken for safety.