Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
The Hacker News reports that an npm worm associated with the Keyv package has compromised hundreds of packages. The worm is designed to plant hooks in both Claude Code and VS Code, two popular development tools. This suggests the attackers are targeting developer workflows to potentially steal credentials, inject malicious code, or gain persistent access to development environments. The attack exploits the trust in Keyv, a widely used key-value storage library, to distribute the malicious payload. The exact number of affected packages is not specified, but the scale is described as 'hundreds.' The worm's ability to modify development tools indicates a sophisticated approach aimed at long-term compromise. The article does not provide specific remediation steps or affected package names, but the incident highlights the ongoing risk of supply chain attacks in the npm ecosystem.
This worm compromises developer tools, potentially affecting many projects and highlighting npm supply chain risks.