SlowMist detected a large-scale npm supply chain attack by MistEye, affecting the Keyv/Cacheable ecosystem. The attacker released over 2000 malicious package versions, including keyv@6.0.0 Keyv is a widely used key value storage abstraction library that supports backends such as Redis, SQLite, PostgreSQL, MongoDB, etc. It is downloaded approximately 127 million times per week, resulting in significant downstream supply chain exposure. The attack technique is highly similar to the Shai Hulud npm worm activity, targeting highly automated and scalable supply chain attacks. Potential attack behaviors include credential theft, environment variable leakage, CI/CD key leakage, remote payload delivery, and horizontal propagation through the invaded development environment.