Published: 04 Aug 2026 › Updated: 04 Aug 2026
New NPM Supply Chain Attack, so I released a new scanner.
After discovering a new supply chain attack today, I created a quick scanner like my Tanstack scanner that discovers any compromised packages on your system.
You can find it here:
https://github.com/officiallymarky/keyvmalwarescanner
There are no dependencies, so no risk of being compromised while scanning.
Just git clone, then run ./scan.sh. That's it.
[mal@serenity keyvscanner]$ ./scan.sh
=== Keyv / Cacheable Supply-Chain IOC Scanner ===
Running on linux x64 at 2026-08-04T16:09:24.531Z
Package indicators: 2234 exact name/version pairs
Indicator source: https://socket.dev/api/public/supply-chain-attacks/keyv-and-cacheable-compromise/packages.csv
Scan roots: /tmp, /opt, /etc, /home/mal, /usr/local
Scanned 3869759 files; skipped 25 unreadable directories.
No known Keyv / Cacheable campaign indicators found.
Super easy, barely an inconvenience.
Leave New NPM Supply Chain Attack, so I released a new scanner. to:
Read more #security posts
Best Posts From Marky
We have not curated any of themarkymark's posts yet. But you can encourage our curation team to review posts by visiting them regularly and by referring other readers. Because we give priority to frequently read content.
More Posts From Marky
- New NPM Supply Chain Attack, so I released a new scanner.
- Arch Linux disables package adoption due to influx of malicious adoptions
- Tan Stack Scanner
- New LLM benchmark: llmtester
- Receive proactive alerts when your openclaw instance is unavailable
- My two favorite Openclaw hacks
- If you are running openclaw, make sure you are updated.
- Some things I wish someone told me when I setup Openclaw
- If you are running openclaw, make sure you are updated.
- Hive Hot or Not improvements