Utopia Tech
SecurityAI-assisted1 min read

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

A credential-stealing worm originating in the npm package keyv@6.0.0 rapidly propagated across the npm ecosystem on August 4, 2026, infecting hundreds of packages across multiple organizations. The malware, which includes hooks targeting Claude Code and VS Code development environments, was confirmed in at least 353-868 packages depending on the monitoring source, representing a significant supply

UT

Utopia Tech

August 4, 2026 · 1 min read

Share

A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 package names in the npm registry. Its monitoring put the wider footprint at 442 versions across 353 names, while Aikido later reported at least 868 packages

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content