NPM Worm Linked to Keyv Poisons Packages, Targets Developer Tools

NPM Worm Linked to Keyv Poisons Packages, Targets Developer Tools

A supply chain attack involving an npm worm has compromised hundreds of packages, injecting malicious hooks into VS Code and Claude Code, threatening developer workflows and web applications.

A newly identified attack on the npm ecosystem is raising alarm among developers and website operators. According to reports, a worm linked to the popular Keyv key-value store library has been poisoning hundreds of npm packages. The malicious payload is designed to plant hooks into Claude Code and Visual Studio Code (VS Code), two widely used tools in software development workflows.

The Keyv library is an open-source key-value store for Node.js, commonly used for caching and data storage in web applications. By attaching to Keyv-associated packages, the worm can spread rapidly through dependency chains, potentially affecting a vast range of projects that rely on these modules. Once installed, the malware injects hooks into development environments, allowing attackers to execute arbitrary code when developers build or run their projects.

For website owners and IT teams, this incident underscores the persistent danger of supply chain compromises. Infected packages can lead to backdoors in production systems, data theft, or further propagation across internal networks. Developers who use npm packages in their web projects must scrutinize dependencies and monitor for unusual behavior, especially in tools like VS Code that are integral to the development process.

AEU Hosting provides security-first managed WordPress hosting, isolating customer environments and applying rigorous monitoring to detect anomalies that could result from compromised dependencies. By maintaining a hardened hosting platform, AEU helps protect websites from the ripple effects of supply chain attacks like this npm worm.

Related AEU services