thehackernews.com 8/4/2026, 2:29:14 PM · external

New npm worm tied to Keyv compromises hundreds of packages

New npm worm tied to Keyv compromises hundreds of packages
CyberSIXT Evidence Panel Source marked as original reporting

THE article reports on the discovery of a new npm worm linked to the Keyv package, which has compromised hundreds of npm packages. This malicious code includes hooks for the Claude code and Visual Studio Code, posing significant risks in supply chain security. The worm's ability to infiltrate numerous packages highlights vulnerabilities in the development ecosystem and underscores the need for enhanced security measures among developers. The report emphasizes the urgency of addressing such malware to protect coding environments and prevent potential exploits.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline