By Interestana AI Editorial — AI-drafted, human-overseen. How we report
NPM Worm Infects Hundreds of Packages With Malicious Code

A sophisticated npm worm, initially identified within the keyv package version 6.0.0, has expanded its reach significantly, infecting hundreds of software packages across multiple organizations. The malicious code first surfaced in the Keyv and Cacheable namespaces before spreading more broadly. On August 4, 2026, security firm SafeDep confirmed the presence of 353 poisoned versions affecting 79 distinct package names within the npm registry. Their monitoring indicated a wider impact, with 442 compromised versions across 353 unique package names. Further analysis by Aikido Security revealed an even larger scope, reporting at least 868 affected packages. The worm's primary objective is credential theft, but it also injects malicious code designed to hook into popular development tools and services. Specifically, the malware has been observed planting code that targets the Claude AI chatbot and the Visual Studio Code (VS Code) integrated development environment. This dual-pronged attack vector suggests an intent to compromise sensitive user data and potentially gain further access through developer tools. The worm's propagation method leverages the extensive dependency chains within the JavaScript ecosystem, where a single compromised package can lead to the infection of numerous downstream projects. The npm registry, a central repository for JavaScript packages, serves as the primary distribution channel for these poisoned libraries. The discovery highlights ongoing vulnerabilities in software supply chains, where malicious actors can exploit the trust placed in open-source packages to distribute malware. The attackers appear to be systematically targeting popular libraries to maximize their impact. The nature of the injected code, which includes hooks for Claude and VS Code, indicates a targeted approach to exploit common developer workflows and sensitive information stored within these environments. This incident underscores the critical need for enhanced security measures in package management and continuous monitoring of open-source dependencies to prevent widespread compromise. The scale of the infection, with hundreds of packages affected, presents a significant risk to developers and organizations relying on the npm ecosystem for their software development. The worm's ability to spread across different namespaces and organizations demonstrates a sophisticated understanding of package management systems and a deliberate effort to achieve broad distribution. The security implications are substantial, as stolen credentials could lead to account takeovers, data breaches, and further malicious activities. The ongoing investigation aims to fully understand the extent of the compromise and to develop effective countermeasures to remove the malicious code and secure the affected packages. The incident serves as a stark reminder of the persistent threats within the digital landscape and the importance of robust cybersecurity practices throughout the software development lifecycle. The attackers' focus on popular tools like Claude and VS Code suggests a strategy to leverage the trust developers place in these platforms to facilitate their malicious objectives. The sheer number of affected packages indicates a well-coordinated and executed campaign, posing a significant challenge for remediation efforts.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.