Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)

Summary

A compromised npm package, keyv/cacheable, has been discovered, but defenders are warned against immediately revoking tokens. Revoking the stolen token is precisely what triggers the malicious payload within this specific incident.

IFF Assessment

FOE

The discovered compromise and the mechanism by which the payload is activated pose a direct threat to defenders, making it bad news.

Defender Context

This incident highlights a novel attack vector in supply-chain compromises where standard incident response procedures can inadvertently activate malware. Defenders need to be aware of this specific technique to avoid triggering the payload when investigating compromised npm packages.

Read Full Story →