Marky avatar

New NPM Supply Chain Attack, so I released a new scanner.

themarkymark

Published: 04 Aug 2026 › Updated: 04 Aug 2026New NPM Supply Chain Attack, so I released a new scanner.

New NPM Supply Chain Attack, so I released a new scanner.

image.png

After discovering a new supply chain attack today, I created a quick scanner like my Tanstack scanner that discovers any compromised packages on your system.

You can find it here:
https://github.com/officiallymarky/keyvmalwarescanner

There are no dependencies, so no risk of being compromised while scanning.

Just git clone, then run ./scan.sh. That's it.

[mal@serenity keyvscanner]$ ./scan.sh
=== Keyv / Cacheable Supply-Chain IOC Scanner ===
Running on linux x64 at 2026-08-04T16:09:24.531Z
Package indicators: 2234 exact name/version pairs
Indicator source: https://socket.dev/api/public/supply-chain-attacks/keyv-and-cacheable-compromise/packages.csv
Scan roots: /tmp, /opt, /etc, /home/mal, /usr/local


Scanned 3869759 files; skipped 25 unreadable directories.
No known Keyv / Cacheable campaign indicators found.

Super easy, barely an inconvenience.

Leave New NPM Supply Chain Attack, so I released a new scanner. to:

Written by

Browncoat | Meme Connoisseur | Bitcoin Evangelist | Dev | Gamer | Technical Samurai | AI Nerd | Hive Witness | Black Belt in Dad Jokes

Read more #security posts


Best Posts From Marky

We have not curated any of themarkymark's posts yet. But you can encourage our curation team to review posts by visiting them regularly and by referring other readers. Because we give priority to frequently read content.

More Posts From Marky