keyv 6.0.0
Obfuscated preinstall payload executes code
Obfuscated JavaScript targets AWS and GitHub runner credentialsPreinstall executes obfuscated bundled eval dropper
SHA-256d584f9b6af48b7ed1f93713944f033783bf149e1c25e1643eb8c0e9df5dc7782
Also flagged by https://safedep.io/rss.xml (Introducing SafeDep Threat Intel), https://www.aikido.dev/blog/rss.xml (The dark figure of supply chain detection), osv (MAL-2026-11524: Malicious code in keyv (npm)) +5 more.