
Lourenço Santos
@lourenco0 followers267 downloads29 copies0 likes151 views
15 detections
Filters
Last updated
All Time
Detection languages
15
Categories
5
3
3
2
1
Platforms
7
7
5
1
1
Products / Services
4
3
3
2
1
MITRE Techniques
6
6
5
4
4
Detects execution of a 'setup.mjs' preinstall lifecycle hook, the stage-1 loader used in the
4 August 2026 compromise of the keyv and cacheable npm namespaces. The trojanised package.json
adds "preinstall": "node setup.mjs" while leaving dist/ byte-identical to the last clean
release, so the only execution-time signal is the hook itself. The loader downloads a
standalone Bun runtime and executes an obfuscated second stage (Math_Symbol.js).
4 August 2026 compromise of the keyv and cacheable npm namespaces. The trojanised package.json
adds "preinstall": "node setup.mjs" while leaving dist/ byte-identical to the last clean
release, so the only execution-time signal is the hook itself. The loader downloads a
standalone Bun runtime and executes an obfuscated second stage (Math_Symbol.js).
Detects a Node or Bun process reaching the cloud instance metadata service. The keyv/cacheable
stage-2 collector targets EC2 IMDS and ECS task metadata as the entry point to a broader sweep
covering AWS credential chains and Secrets Manager across all regions, GCP service account
keys, Azure client secrets, HashiCorp Vault tokens, Kubernetes service account tokens, GitHub
Actions OIDC request tokens and npm tokens. On a build agent this pattern is the clearest
signal that credential theft is in progress.
stage-2 collector targets EC2 IMDS and ECS task metadata as the entry point to a broader sweep
covering AWS credential chains and Secrets Manager across all regions, GCP service account
keys, Azure client secrets, HashiCorp Vault tokens, Kubernetes service account tokens, GitHub
Actions OIDC request tokens and npm tokens. On a build agent this pattern is the clearest
signal that credential theft is in progress.
Detects creation of the stage-2 payload files distributed with the compromised keyv and
cacheable packages. Math_Symbol.js is a ~728 KB Bun bundle shipped in the tarball and written
to disk as math_init.js by the loader; bun-dl-* directories are used to stage the downloaded
Bun runtime. These filenames are specific to the campaign and should be treated as high
fidelity indicators.
cacheable packages. Math_Symbol.js is a ~728 KB Bun bundle shipped in the tarball and written
to disk as math_init.js by the loader; bun-dl-* directories are used to stage the downloaded
Bun runtime. These filenames are specific to the campaign and should be treated as high
fidelity indicators.
Detects a Node or Bun process reading Kubernetes service account tokens or HashiCorp Vault
token files. The keyv/cacheable collector reads these paths directly as part of its credential
sweep. Companion rule to the IMDS detection (d02b7df0-60e3-4ec9-a077-339507299e11).
token files. The keyv/cacheable collector reads these paths directly as part of its credential
sweep. Companion rule to the IMDS detection (d02b7df0-60e3-4ec9-a077-339507299e11).
Temporal correlation of the two highest-confidence stages of the keyv/cacheable compromise:
a setup.mjs preinstall hook executing, followed within 15 minutes on the same host by a Bun
runtime executing from a staging or node_modules path. Either alone is tunable noise on a
developer estate; the pair is the campaign. Use this as the alerting rule and keep the base
rules at correlation-input severity.
a setup.mjs preinstall hook executing, followed within 15 minutes on the same host by a Bun
runtime executing from a staging or node_modules path. Either alone is tunable noise on a
developer estate; the pair is the campaign. Use this as the alerting rule and keep the base
rules at correlation-input severity.
Detects execution of a Bun binary from a temporary, download-staging or node_modules path
rather than a standard installation location. The keyv/cacheable stage-1 loader downloads a
platform-matched standalone Bun runtime from the oven-sh GitHub release URL and uses it to
execute the second stage, specifically to bypass the host Node version and any Node-level
monitoring. Staging directories follow a 'bun-dl-*' naming pattern.
rather than a standard installation location. The keyv/cacheable stage-1 loader downloads a
platform-matched standalone Bun runtime from the oven-sh GitHub release URL and uses it to
execute the second stage, specifically to bypass the host Node version and any Node-level
monitoring. Staging directories follow a 'bun-dl-*' naming pattern.
Detects a Node or Bun process writing to Claude Code or VS Code autostart configuration. The
keyv/cacheable campaign plants a SessionStart hook in .claude/settings.json and a folderOpen
task in .vscode/tasks.json inside the trojanised source repository. Both execute the stage-1
loader when a developer or an AI coding agent opens the cloned repo, with no npm install
required - so lockfile pinning and registry blocking do not cover this path.
Note: this is the highest-value rule in the set for the agentic AI estate. It is also the one
most likely to need tuning, since tasks.json is legitimately written by many tools.
keyv/cacheable campaign plants a SessionStart hook in .claude/settings.json and a folderOpen
task in .vscode/tasks.json inside the trojanised source repository. Both execute the stage-1
loader when a developer or an AI coding agent opens the cloned repo, with no npm install
required - so lockfile pinning and registry blocking do not cover this path.
Note: this is the highest-value rule in the set for the agentic AI estate. It is also the one
most likely to need tuning, since tasks.json is legitimately written by many tools.
Detects network connections to hardcoded threat-actor IPs used by the VPN Go extensions for clipboard exfiltration (/html/continue.php) and proxy-location retrieval (/locations). Covers Chrome 1.1-1.3 and Firefox 1.3.3-1.3.4 infrastructure.
Detects outbound HTTP requests matching the VPN Go clipboard-stealer exfiltration pattern: a request to /html/continue.php carrying the uid, part, total, and data query parameters used to reassemble chunked clipboard contents server-side. URI-pattern based, so it catches infrastructure rotation beyond the known IOC hosts.
Detects presence of the malicious Chrome extension ID in process command lines, file paths, or registry/preferences artifacts on managed endpoints. Tune logsource to your collection (Sysmon process_creation shown).
Page 1 of 2
