A worm tied to the Keyv package ecosystem reportedly compromised hundreds of npm packages, putting developers and systems that install them at risk. The attack is a supply-chain compromise in the Node.js package registry in which malicious package updates spread through package relationships and plant hooks in developer tools including Claude Code and Visual Studio Code for persistence or follow-on abuse. The article text provided does not include CVE IDs or confirmed package/version lists.
Arctic Wolf
2026.08.06
98% relevant
This source is a direct update on the same npm supply-chain attack, adding specific impacted package names and versions, attacker tradecraft including the setup.mjs loader and Math_Symbol.js payload, Bun runtime download behavior, credential theft and GitHub-based exfiltration, and concrete mitigation guidance for dependency audits, downgrades, and credential rotation.
Ionut Arghire
2026.08.05
97% relevant
This article reports the same underlying ChainDrop/Mini Shai-Hulud campaign, adding scope and technical detail: 440 packages, 2,212 malicious versions, compromise of the keyv and cacheable namespaces via a maintainer GitHub account, propagation through stolen npm and GitHub credentials, theft of cloud and CI/CD secrets, and EtherHiding-based command-and-control.
Bill Toulas
2026.08.04
97% relevant
This is the same underlying ChainDrop/Keyv npm supply-chain event and adds concrete scope and mechanics: BleepingComputer reports more than 1,300 compromised package versions, names additional affected package families and organizations, describes the setup.mjs and Math_Symbol.js payload chain, notes Bun runtime abuse, and details stolen GitHub, npm, cloud, Kubernetes, Vault, and CI/CD secrets plus the npm-cache[.]com indicator.
info@thehackernews.com (The Hacker News)
2026.08.04
100% relevant
This article appears to establish a distinct supply-chain incident centered on a Keyv-linked npm worm and its developer-tool persistence behavior, rather than clearly updating an already tracked specific package-compromise event.