Keyv-linked npm worm poisons hundreds of JavaScript packages and adds Claude Code and VS Code persistence hooks

A worm tied to the Keyv package ecosystem reportedly compromised hundreds of npm packages, putting developers and systems that install them at risk. The attack is a supply-chain compromise in the Node.js package registry in which malicious package updates spread through package relationships and plant hooks in developer tools including Claude Code and Visual Studio Code for persistence or follow-on abuse. The article text provided does not include CVE IDs or confirmed package/version lists.
Why it matters: Developers and organizations using affected npm packages could unknowingly run attacker code and have their coding environments tampered with. Teams should identify any impacted packages, halt installs or updates until they verify clean versions, review Claude Code and VS Code configurations for unauthorized hooks, and rotate exposed secrets.

Sources

Active Supply Chain Attack on npm Packages (keyv, cacheable): Immediate Mitigation Required
Arctic Wolf 2026.08.06 98% relevant
This source is a direct update on the same npm supply-chain attack, adding specific impacted package names and versions, attacker tradecraft including the setup.mjs loader and Math_Symbol.js payload, Bun runtime download behavior, credential theft and GitHub-based exfiltration, and concrete mitigation guidance for dependency audits, downgrades, and credential rotation.
Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
Ionut Arghire 2026.08.05 97% relevant
This article reports the same underlying ChainDrop/Mini Shai-Hulud campaign, adding scope and technical detail: 440 packages, 2,212 malicious versions, compromise of the keyv and cacheable namespaces via a maintainer GitHub account, propagation through stolen npm and GitHub credentials, theft of cloud and CI/CD secrets, and EtherHiding-based command-and-control.
Massive ChainDrop npm supply-chain attack infects hundreds of packages
Bill Toulas 2026.08.04 97% relevant
This is the same underlying ChainDrop/Keyv npm supply-chain event and adds concrete scope and mechanics: BleepingComputer reports more than 1,300 compromised package versions, names additional affected package families and organizations, describes the setup.mjs and Math_Symbol.js payload chain, notes Bun runtime abuse, and details stolen GitHub, npm, cloud, Kubernetes, Vault, and CI/CD secrets plus the npm-cache[.]com indicator.
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
info@thehackernews.com (The Hacker News) 2026.08.04 100% relevant
This article appears to establish a distinct supply-chain incident centered on a Keyv-linked npm worm and its developer-tool persistence behavior, rather than clearly updating an already tracked specific package-compromise event.
← Back to all stories