NewsThe keyv npm Attack: Signed, Verified, and MaliciousThe keyv and cacheable npm packages shipped a credential stealer with valid provenance. What it did, how to check if you're hit, and what to fix first.Aug 7, 2026·9 min