#3
The Hacker News
general
August 04, 2026 at 13:30 UTC
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
By [email protected] (The Hacker News)
AI Summary
A credential-stealing npm worm originating in [email protected] spread to at least 868 packages across 353 package names by August 4, 2026, with SafeDep verifying 353 poisoned versions across 79 package names. The worm plants Claude Code and VS Code hooks as persistence mechanisms, targeting developer toolchains directly. This incident follows the broader ChainDrop campaign and signals an escalating wave of self-replicating supply-chain attacks on npm.
Relevance score: 90.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →