Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
A sophisticated npm worm, linked to the Keyv vulnerability and attributed to the Shai-Hulud threat actor family, has spread across hundreds of packages, injecting credential-stealing and malicious code. The worm leverages preinstall scripts to harvest sensitive data – including GitHub, npm, cloud, and private keys – and then uses stolen npm identities to poison more packages. Initial analysis indicates a complex, automated campaign with a significant scope, but definitively identifying the actors and precise number of compromised systems remains challenging due to the dynamic nature of package tags and the use of automated publishing.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
