Your code's "hidden" vendors: the Keyv/NPM case and third-party risk
On August 4, 2026, attackers compromised the GitHub account of the developer who maintains keyv, a widely used open-source JavaScript library, and used it to push malicious code into keyv and a family of related caching packages. keyv alone is downloaded around 127 million times a week, so the