npm provenance signed the malware on 4 August 2026: what attestations prove and what a cooldown stops
Valid provenance signed keyv 6.0.0 on 4 August 2026, and eight malicious releases were still tagged latest 101 minutes later. What attestations prove, and the cooldown config for npm, pnpm, Yarn and Bun.