On August 4, 2026, several high-profile npm packages were compromised and used to propagate a backdoor. Commit 174f6a5 on the keyv npm package is an example of the malicious payload used as part of this campaign.
Some of the compromised packages are highly popular. For instance, keyv, file-entry-cache, and flat-cache each individually total 150 million monthly downloads. We believe the payload has the ability to spread to adjacent npm packages.
How to know if you're affected
While the situation is quickly evolving, we're publishing below a dynamic list of npm packages that were compromised as part of this campaign and distribute a malicious payload. You can access a CSV version on our GitHub repository.
Show the list of compromised npm packages
Loading latest data…
Developing situation
This is a developing situation and we'll publish an in-depth analysis of this campaign in the coming hours.
How Datadog can help
Datadog Code Security can identify hosts, containers, and build environments where the compromised version was installed. Refer to the in-app Security Research Feed card for more information.
Datadog also maintains the open source supply-chain security firewall (SCFW), which can proactively block known malicious packages at installation time. It can also log every single npm and PyPI package installed on a developer's workstation and ship it to your Datadog organization, allowing you to react when new malicious or compromised packages are discovered.