{"data":{"id":"1e7b60d5-7163-41ec-8d21-d2243dd36828","title":"Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks","summary":"A malicious npm package called keyv@6.0.0 spread to hundreds of packages in August 2026, using a preinstall script (code that runs automatically when a package is installed) to steal credentials like passwords and API keys from developer machines and CI environments (continuous integration systems that automatically test and deploy code). The worm could also plant hidden hooks in VS Code and Claude Code editors that execute the malicious code when a developer opens the project.","solution":"SafeDep advises responders to remove the malware's credential-revocation watcher before rotating exposed tokens and keys, since revocation is the watcher's trigger and rotating first can run an attacker-supplied local handler. Additionally, npm 12 blocks unapproved dependency lifecycle scripts by default, protecting users on that version going forward.","labels":["security"],"sourceUrl":"https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html","publishedAt":"2026-08-04T13:30:23.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"critical","attackType":["supply_chain","data_extraction"],"issueType":"news","affectedPackages":null,"affectedVendors":["Anthropic","Microsoft"],"affectedVendorsRaw":["Anthropic","Microsoft","Claude Code","VS Code","npm","GitHub","Vault","Kubernetes"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-08-04T13:30:23.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality","integrity"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}