
Massive npm Worm Compromises Hundreds of Packages in Supply Chain Attack
CybersecurityMalwareSupplyChainAttacksPackageEcosystemThreats
A credential-stealing npm worm initially detected in keyv@6.0.0 expanded beyond the Keyv and Cacheable namespaces, compromising hundreds of packages across multiple organizations on August 4, 2026. Security firm SafeDep confirmed 353 poisoned versions across 79 package names in the npm registry, estimating a broader impact of 442 versions across 353 names, while Aikido later reported at least 868 affected packages. The worm embedded malicious code, including Claude-related components and VS Code hooks, to exfiltrate sensitive data. No CVE IDs were specified in the incident. The attack targeted the npm ecosystem, leveraging dependency chains to propagate.