VDB

GCVE-110-OSM-2026-9651

GCVE-110-OSM-2026-9651
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 4, 2026
Compromised version 6.0.0 of keyv (604M monthly downloads) via hijacked maintainer GitHub account in the Shai-Hulud supply chain attack. The attacker pushed malicious files directly to main and cut a new release with valid GitHub Actions signatures. The malicious preinstall script downloads the Bun runtime and executes a 728KB obfuscated payload (Math_Symbol.js) that steals npm tokens, GitHub tokens, AWS credentials, Kubernetes secrets, HashiCorp Vault tokens, Stripe keys, Slack tokens, SSH keys, and ~200 categories of sensitive files. Stolen data is exfiltrated to a GitHub repository. Contains worm functionality to propagate to other maintainers packages. === PAYLOAD 1: Dropper (setup.mjs) === Malicious payload found in: setup.mjs Trigger: preinstall script in package.json: node setup.mjs Behavior: Heavily obfuscated dropper that downloads the Bun JavaScript runtime from github.com/oven-sh/bun/releases/download/bun-v1.3.13/ and executes the main payload === PAYLOAD 2: Infostealer (Math_Symbol.js) === Malicious payload found in: Math_Symbol.js (728 KB) Execution: execFileSync(bun binary, Math_Symbol.js) Behavior: Steals npm tokens, GitHub tokens (ghp_, gho_, ghs_, JWT OIDC), AWS credentials (files, env vars, EC2/ECS metadata, Secrets Manager), Kubernetes secrets, HashiCorp Vault tokens, Stripe keys, Slack tokens, SSH keys, .env files, private keys, Terraform state, Docker configs, KeePass databases, VPN configs. Uses 64 concurrent reads. Exfiltrates encrypted data to GitHub repo. Contains worm propagation to infect other maintainers packages.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownkeyv6.0.0 (affected)

References

vendor

Browse GCVE Records

67,506 records in the GCVE database · Updated August 11, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›