logo

Worm compromises hundreds of popular npm packages

ID: 135e6b15-7700-5188-b045-ad20f566f59c

STIX ID: report--135e6b15-7700-5188-b045-ad20f566f59c

Feed Name: Datadog Security Labs

Threat Score
90/100

Date Published: 2026-08-04

Date Updated: 2026-08-06

...
...

On 2026-08-04 a widespread npm supply-chain campaign was observed that injected a two-stage loader into popular packages (including keyv, cacheable, and ecto) to execute a Bun-based second stage which harvests secrets (GitHub, npm, cloud, CI, Kubernetes, Vault, AWS), exfiltrates encrypted data using an Ethereum smart-contract dead-drop or GitHub repository fallback, and propagates by publishing malicious package updates and committing repository hooks and workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.