On August 4, ten npm packages from the keyv and cacheable projects were published with a malicious preinstall hook. Together they see about 515 million weekly downloads, keyv, flat-cache, file-entry-cache, and cache-manager among them. They sit deep under tools most JavaScript teams run, which is how hundreds of downstream packages ended up carrying the payload.
The chain was a single maintainer account. With it, the attacker published through the normal pipeline with valid tokens. The preinstall script downloaded a runtime, ran a 727 kilobyte obfuscated second stage, and deleted itself. The second stage harvested credentials and installed a dead man's switch that polls GitHub every sixty seconds with the stolen token and runs attacker-supplied code the moment that token is revoked.
Two things I take from it. First, the advice to sweep a machine for the switch before rotating credentials, because rotating first is the trigger.
Second, and more generally: install scripts should be off by default in every front-end pipeline, and a minimum release age should be enforced, even at the cost of slower upgrades. One account takeover reached hundreds of millions of installs through a hook most of them did not need. Turning it off costs almost nothing. Leaving it on is a bet on every maintainer's account security, and this month the bet lost.
Does your pipeline run install scripts by default, and does anyone know which packages actually need them?
Photo source: https://photos.robertstowe.com/tasmania

