An active npm supply chain compromise affected widely used packages in the keyv and cacheable ecosystems, along with packages owned by other maintainers. At least ten packages were published with a malicious preinstall hook named setup. mjs .

Source: [Dev.to](https://dev.to/informertech/keyv-and-cacheable-npm-supply-chain-compromise-4n6e)

Sponsored