Massive npm Supply Chain Attack Hits Hundreds of Packages via Keyv Worm
A credential-stealing worm first discovered in the popular npm package 'keyv' has spread rapidly across the npm registry, a repository widely used by developers to share and reuse code. Security researchers confirmed the malicious code, which began in [email protected], has since infected packages well beyond the original Keyv and Cacheable namespaces, spreading across multiple unrelated organisations' projects.
Different security firms tracking the incident reported varying but consistently alarming numbers: SafeDep verified 353 poisoned versions across 79 package names, with its broader monitoring identifying 442 affected versions across 353 package names. Aikido, another security research firm, reported an even larger footprint of at least 868 compromised packages. The worm reportedly plants hooks into developer tools such as Claude Code and Visual Studio Code, potentially giving attackers a foothold to steal credentials from affected systems.
Because npm packages are building blocks used in countless applications and websites, a compromise like this can quietly spread malicious code into software used by businesses that have no direct connection to the original infected package. Australian small businesses that rely on developers, contractors, or custom software built using npm-based tools should be aware that this type of supply chain attack can introduce risk without any obvious warning signs.