CyberSecurity News
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
AI summary
A credential-stealing npm worm initially found in keyv@6.0.0 has spread to hundreds of packages across multiple organizations. The worm was detected on August 4, 2026, and has affected packages beyond the Keyv and Cacheable namespaces. SafeDep verified 353 poisoned versions across 79 package names in the npm registry, and its monitoring indicated a wider impact of 442 versions across 353 names. Aikido later reported that at least 868 packages were affected by the worm. The worm plants malicious code and hooks in Claude and VS Code. The spread of the worm has resulted in a significant number of compromised packages in the npm registry.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

