Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)
Summary
A compromised npm package, keyv/cacheable, has been discovered, but defenders are warned against immediately revoking tokens. Revoking the stolen token is precisely what triggers the malicious payload within this specific incident.
IFF Assessment
FOE
The discovered compromise and the mechanism by which the payload is activated pose a direct threat to defenders, making it bad news.
Defender Context
This incident highlights a novel attack vector in supply-chain compromises where standard incident response procedures can inadvertently activate malware. Defenders need to be aware of this specific technique to avoid triggering the payload when investigating compromised npm packages.