Home / Aug 05, 2026 / Story
0
#3 The Hacker News general August 04, 2026 at 13:30 UTC

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

By [email protected] (The Hacker News)

AI Summary

A credential-stealing npm worm originating in [email protected] spread to at least 868 packages across 353 package names by August 4, 2026, with SafeDep verifying 353 poisoned versions across 79 package names. The worm plants Claude Code and VS Code hooks as persistence mechanisms, targeting developer toolchains directly. This incident follows the broader ChainDrop campaign and signals an escalating wave of self-replicating supply-chain attacks on npm.

Relevance score: 90.0/100

# More from August 05