LIVEΒ·
SkylineWire Logo

SkylineWire

Global News & Market Intelligence Β· Verified from Official Dispatches

Editions:
Home
LIVEMARKETS:
S&P 500 5,640.20 (+0.45% β–²)|NASDAQ 17,855.10 (+0.62% β–²)|BRENT CRUDE $82.40 (-0.85% β–Ό)|SAF FUEL $2,140/t (+1.2% β–²)
S&P 500 5,640.20 (+0.45% β–²)|NASDAQ 17,855.10 (+0.62% β–²)|BRENT CRUDE $82.40 (-0.85% β–Ό)|SAF FUEL $2,140/t (+1.2% β–²)
BreakingDeveloping Storyβœ“ Verified Reporting
Cybersecurity· 🌍 Global

NPM Worm Spreads Through Keyv Package Poisoning Hundreds of Libraries

A credential-stealing worm originating in keyv@6.0.0 has compromised hundreds of npm packages, prompting urgent security warnings for software developers.

By Skyline Wire Newsroom Β· Published Source: The Hacker News Β· Verified Reporting

Key Story Metrics & Context

Industry Sector:Technology, Software Development
Companies Impacted:npm, Microsoft, Anthropic
Geographic Scale:Global 🌍
Reporting Status:βœ“ Multi-Source Verified
NPM Worm Spreads Through Keyv Package Poisoning Hundreds of Libraries

Executive Brief & Verified Analysis

βœ“ OFFICIAL SOURCES REVIEWED

Executive Summary

A credential-stealing worm originating in keyv@6.0.0 has compromised hundreds of npm packages, prompting urgent security warnings for software developers.

Why This Matters

Key strategic implication: The attack originated on August 4, 2026, starting with the release of keyv@6.0.0.

Market Impact

Verified for npm, Microsoft, Anthropic. Primary market adjustment vector.

Source Verification

Cross-referenced across regulatory dispatches, official press releases, and verified wire filings.

Strategic Implications

  • βœ“The attack originated on August 4, 2026, starting with the release of keyv@6.0.0.
  • βœ“SafeDep verified 353 poisoned versions across 79 package names.
  • βœ“The malicious worm targets developer tools, including VS Code and Claude Code.
  • βœ“Aikido reports at least 868 packages have been affected by the campaign.

A malicious credential-stealing worm has infiltrated the npm registry, infecting hundreds of packages across various organizations. According to The Hacker News, the campaign first surfaced within the keyv@6.0.0 release on August 4, 2026, before expanding its reach into the Cacheable namespaces and beyond. The malware is designed to install hooks into both Claude Code and VS Code environments to facilitate unauthorized data exfiltration.

Security researchers have provided varying assessments of the infection's scope based on their internal monitoring tools. SafeDep, which conducted an analysis of the registry, confirmed the presence of 353 poisoned versions across 79 distinct package names. Other monitoring services suggest a more pervasive footprint. While SafeDep tracks the incident at 442 versions across 353 names, external reporting from Aikido has identified at least 868 compromised packages affected by this ongoing distribution effort.

Incident Scope and Data

Assessment SourceAffected VersionsAffected Package Names
SafeDep (Verified)35379
SafeDep (Monitoring)442353
Aikido (Reported)868N/A

The rapid proliferation of this worm underscores the persistent risks inherent in the software supply chain. By targeting widely used libraries like Keyv, the attackers leveraged trust in existing dependencies to automate the injection of hooks into developer workstations. Security teams are advised to audit their package-lock files and review recent dependency updates for any signs of unauthorized modifications or suspicious configuration triggers.

Why It Matters

This incident highlights a dangerous evolution in automated supply chain attacks. By specifically targeting VS Code and Claude Code hooks, attackers are moving beyond simple data theft to intercepting the very tools developers use to build future software. This creates a recursive vulnerability where the development environment itself becomes an attack vector. Organizations must shift from passive dependency monitoring to active, behavioral-based analysis of their build pipelines. Relying solely on version pinning is no longer sufficient when high-utility, trusted packages are compromised at the source level, allowing malicious code to bypass standard CI/CD gatekeepers.

Deployment Roadmap & Timeline

August 4, 2026

The npm worm first appears in keyv@6.0.0 and begins spreading to other packages.

Expected Next Steps

  • 1Review current npm dependency trees for the presence of compromised keyv or Cacheable versions.
  • 2Monitor developer endpoints for unauthorized hooks related to VS Code and Claude Code.
  • 3Implement more rigorous integrity checks in CI/CD pipelines to detect downstream dependency changes.

Frequently Asked Questions

The infection originated in the keyv@6.0.0 package, which contained malicious code designed to steal credentials and hook into developer tools.

Estimates vary by security firm: SafeDep verified 353 poisoned versions, while Aikido reported at least 868 packages affected.

The worm is specifically designed to install hooks into VS Code and Claude Code environments.

Source Transparency & Verified Dispatches

βœ“ Verified Primary Data
βœ“
The Hacker NewsπŸ’Ό Corporate Dispatch
Source β†—
βœ“
SafeDepπŸ’Ό Corporate Dispatch
Source β†—
βœ“
AikidoπŸ’Ό Corporate Dispatch
Source β†—

Reader Discussion & Insights

Leave a Comment

Loading discussion thread...

Get Breaking Global Intel in Your Inbox

Subscribe to the Skyline Wire AI Daily Briefing. Direct insights across Aviation, Tech, EVs, and Markets.

Original announcement link: The Hacker News

npmcybersecuritysupply-chain-attackkeyvmalware
npm wormkeyv package vulnerabilitysoftware supply chain attackcredential stealing malwarevs code securitynpm registry poisoning