THE article reports on the discovery of a new npm worm linked to the Keyv package, which has compromised hundreds of npm packages. This malicious code includes hooks for the Claude code and Visual Studio Code, posing significant risks in supply chain security. The worm's ability to infiltrate numerous packages highlights vulnerabilities in the development ecosystem and underscores the need for enhanced security measures among developers. The report emphasizes the urgency of addressing such malware to protect coding environments and prevent potential exploits.
New npm worm tied to Keyv compromises hundreds of packages
CyberSIXT Evidence Panel
Source marked as original reporting
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
npm Supply Chain Attack Hijacks Keyv, Spreads Shai-Hulud Malware
securityonline.info
-
New npm worm tied to Keyv compromises hundreds of packages
thehackernews.com