Keyv-linked npm worm poisons hundreds of packages
๐ก๏ธ A credential-stealing npm worm first seen in keyv@6.0.0 spread beyond Keyv and Cacheable namespaces on August 4, 2026, impacting hundreds of packages. SafeDep verified 353 poisoned versions across 79 package names while other monitors reported larger, harder-to-validate totals. The malicious preinstall script harvested repository, registry, cloud and private-key material, installed a token-revocation watcher and used npm publish access to propagate. Additional execution paths via Claude Code and VS Code workspace hooks could trigger the payload when a user trusts a workspace or permits project configuration.
