ThreatPaper
Unverified

The keyv compromise affected 450 million weekly downloads

Assessment

Three separate things are being conflated into one number. The figure combines the download volume of keyv, flat-cache and file-entry-cache. Snyk, which published the underlying counts, states that "those numbers overlap heavily because the packages depend on one another" and represent ecosystem reach rather than confirmed compromised host counts — pulling keyv often pulls the others, so the same install is counted more than once. The counts also cover a month (5 July to 3 August in Snyk's figures), while the malicious versions were live for hours. Snyk's 11:16 UTC snapshot on the day records three versions already removed and eight still tagged latest, which places the exposure window in single digits of hours rather than weeks. And an install is not an execution. The population that matters is installs during that window which ran the preinstall hook, plus developers who opened an affected repository in an editor or agent session. Neither has been published. Rated Unverified rather than False because the download counts themselves are accurate and honestly sourced. What is unsupported is their use as a measure of harm — the number describes how important these packages are, which is a different and much larger quantity than how many hosts were compromised.

Where this claim appeared

safedep · 2026-08-05

https://safedep.io/keyv-npm-supply-chain-compromise/

What “Unverified” means

Widely repeated, but no supporting evidence was located. This is not a statement that the claim is false — it is a statement that nothing published supports it, which is a different and more common problem.

2 of 5 · rating scale

Assessed in

keyv npm Compromise: A Credential-Stealing Worm That Shipped With Valid Provenance

Think this assessment is wrong? Report an error.