[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3Z3LDNvKtEdqLCDwHsv1xxYWK7C9cj4lS_-O0L_GM3g":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"7ed06494-83e5-4413-a42a-57e76afaca9d","npm-worm-spreads-through-keyv-package-stealing-credentials-and-hijacking-dev-tools","ad184a6e-fb46-49fe-9a64-659d65f8d568","npm Worm Spreads Through keyv Package, Stealing Credentials and Hijacking Dev Tools","A malicious worm injected into the widely-used keyv npm package demonstrates the cascading risk of supply chain attacks: a single compromised dependency can propagate malware to hundreds of downstream packages across multiple organizations. The worm exploits npm's preinstall lifecycle hooks — a legitimate feature — to silently harvest repository credentials, cloud secrets, and private keys before a developer even runs their application. By also planting hooks into trusted developer environments like VS Code and Claude Code, attackers extend their foothold into the developer's local machine, turning trusted workspaces into persistent attack surfaces. This incident underscores why blindly trusting third-party packages, even well-known ones, creates systemic risk across entire software ecosystems.","**Immediate actions:**\n- Audit all projects using keyv and any transitive dependencies for versions >=6.0.0 and downgrade or patch to a verified clean release immediately.\n- Rotate all secrets, API keys, cloud credentials, and private keys that may have been exposed in affected development environments.\n- Scan npm preinstall\u002Fpostinstall scripts across your dependency tree for suspicious or obfuscated commands using tools like `npm audit` or Socket.dev.\n\n**Long-term improvements:**\n- Enforce a policy of pinning exact dependency versions and using lock files (package-lock.json, yarn.lock) to prevent silent version drift to malicious releases.\n- Implement a private npm registry or artifact proxy (e.g., Artifactory, Verdaccio) to vet and cache approved package versions before they reach developer machines.\n- Adopt software composition analysis (SCA) tools in CI\u002FCD pipelines to continuously monitor third-party packages for newly introduced malicious behavior.\n\n**Detection measures:**\n- Monitor developer endpoints and CI\u002FCD environments for unexpected outbound network connections initiated during package installation phases.\n- Enable IDE and workspace trust policies in VS Code to restrict automatic execution of workspace-level scripts from untrusted sources.\n- Set up alerts for unexpected modifications to VS Code settings files (settings.json, tasks.json) or Claude Code configuration files on developer machines.",[12,13,14,15,16,17,18,19,20],"CIS Control 2 – Inventory and Control of Software Assets","CIS Control 16 – Application Software Security","NIST SP 800-161 – Supply Chain Risk Management Practices","NIST SP 800-218 – Secure Software Development Framework (SSDF) – PW.4 (Reuse Well-Secured Software)","NIST CSF DE.CM-3 – Personnel activity is monitored to detect cybersecurity events","NIST CSF ID.SC-4 – Suppliers are routinely assessed","SLSA Supply Chain Security Framework – Level 2+ (Provenance and dependency verification)","OWASP A06:2021 – Vulnerable and Outdated Components","GDPR Article 32 – Security of processing (applicable where personal data is handled in affected environments)","published","2026-08-04T16:21:59.919742+00:00","2026-08-04T16:21:59.798+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fkeyv-linked-npm-worm-poisons-hundreds.html","keyv-linked-npm-worm-poisons-hundreds-of-packages-plants-claude-code-and-vs-code-4b6302","Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]