news.mlab.sh
9 results
threat-intel

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

A sophisticated npm worm, linked to the Keyv vulnerability and attributed to the Shai-Hulud threat actor family, has spread across hundreds of packages, injecting credential-stealing and malicious code. The worm leverages preinstall scripts to harvest sensitive data – including GitHub, npm, cloud, and private keys – an…

The Hacker News · Aug 4, 2026 High