Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

Summary

A credential-stealing npm worm has compromised hundreds of packages, extending its reach beyond its initial targets. The worm has been observed injecting malicious code, including what appears to be Claude code and VS Code hooks, into these packages.

IFF Assessment

FOE

The npm worm's ability to spread to hundreds of packages and inject malicious code represents a significant threat to the software supply chain and developers.

Defender Context

This incident highlights the ongoing threat of supply chain attacks within the npm ecosystem. Defenders should be vigilant about package integrity, implement robust dependency scanning, and monitor for unusual code behavior in their development pipelines.

Read Full Story →