logo

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

ID: f465b635-62a2-574e-94fa-657376a0734a

STIX ID: report--f465b635-62a2-574e-94fa-657376a0734a

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-08-04

Date Updated: 2026-08-04

Author: [email protected] (The Hacker News)

...
...

A credential‑stealing npm worm (first observed in [email protected]) used a preinstall lifecycle script and repository/IDE hooks to harvest GitHub, npm, cloud, Vault, Kubernetes, database and private‑key credentials and then use stolen npm publishing access to propagate across hundreds to thousands of package names and versions; researchers (SafeDep, Socket, Aikido) reported large, rapidly spreading infection counts and advise treating any environment that executed an affected release as compromised, comparing resolved versions/lockfiles, disabling unnecessary install scripts, and carefully rotating credentials after removing the malware's revocation watcher.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.