Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
Overview
A credential-stealing worm linked to the npm package 'keyv' has spread to hundreds of packages since it was first identified on August 4, 2026. This malware has affected at least 868 packages according to Aikido, with SafeDep confirming 353 poisoned versions across 79 package names in the npm registry. The worm is designed to steal user credentials and has also incorporated hooks for the Claude code and Visual Studio Code environments. This incident raises serious concerns for developers and organizations using these packages, as compromised libraries can lead to significant security breaches and data loss. Users are urged to audit their dependencies and ensure they are using safe versions of affected packages.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: keyv@6.0.0, Cacheable namespaces, 868 npm packages
- Action Required: Users should audit their npm packages and update to secure versions as they become available.
- Timeline: Ongoing since August 4, 2026
Original Article Summary
A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 package names in the npm registry. Its monitoring put the wider footprint at 442 versions across 353 names, while Aikido later reported at least 868 packages
Impact
keyv@6.0.0, Cacheable namespaces, 868 npm packages
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since August 4, 2026
Remediation
Users should audit their npm packages and update to secure versions as they become available. Specific versions to avoid include keyv@6.0.0 and other identified compromised packages.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Malware.