
CRITICALAn urgent, high-impact development that requires immediate attention.Security
npm Package Hijacks Turn Dependency Trees Into Incident Scope
The keyv/cacheable investigation is a reminder that a compromised npm dependency can spread through transitive resolution, not just direct imports. Teams need to scope exposure from build evidence and deployed artifacts.