Malicious npm Preinstall Hook - setup.mjs (keyv/cacheable Compromise)
Detects execution of a 'setup.mjs' preinstall lifecycle hook, the stage-1 loader used in the 4 August 2026 compromise of the keyv and cacheable npm namespaces. The trojanised package.json adds "preinstall": "node setup.mjs" while leaving dist/ byte-identical to the last clean release, so the only execution-time signal is the hook itself. The loader downloads a standalone Bun runtime and executes an obfuscated second stage (Math_Symbol.js).
Sigma

