keyv Worm Hit 868 npm Packages. Check Your Lockfile Now
On August 4, 2026, attackers compromised the GitHub account of the maintainer behind `keyv`, a key-value storage library with roughly 127 million weekly npm downloads. And used that access to inject a credential-stealing worm across the entire package family. International Cyber Digest reported the attack compromised at least 868 npm