On 4 August a poisoned version of keyv started spreading through npm - it steals tokens and keys, republishes itself under someone else's name, and plants hidden commands. Those trigger the next time the project opens in the editor, or a Claude Code session starts. The signatures were valid: the source was poisoned before the build.
- A hijacked maintainer account published poisoned keyv@6.0.0 (04.08, 09:35 UTC); the worm spreads using stolen npm tokens and, per Datadog's analysis, reaches hundreds of packages.
- The payload steals SSH keys, GitHub and npm tokens, and cloud credentials - and plants hooks in .claude/settings.json and .vscode/tasks.json that run it again when the project opens.
- The poisoned versions carry valid npm provenance attestation. Defense: npm install with --ignore-scripts, pinning clean versions, reviewing .claude/ and .vscode/, rotating tokens.
If npm install ran anywhere in the world yesterday, there's a real chance that machine is already leaking keys to a foreign server. Open the project afterward with Claude Code or VS Code, and the infection has left a backup entry - a backdoor - too.
Here's what isn't obvious at first glance: the attacker is now counting agents as a door too. The hook in .claude/settings.json waits for the exact moment a person or an agent says 'I trust this folder'. Until now the supply chain went after CI servers and developer laptops. This attack goes after the AI assistant's settings too - because it knows trust gets handed out there with one keystroke, and afterward nobody looks at what's actually written inside.
The second uncomfortable truth is the attestation. The release is signed, with valid provenance, passing every green check - because the source code it's built from was already poisoned. The signature guarantees who assembled the package and which shelf it came from. What's inside it, it never promised.
We run npm install with the --ignore-scripts flag while the dust settles. Versions get pinned. For keyv that's 5.6.0. In every repo touched these days, .claude/ and .vscode/ get reviewed line by line. GitHub and npm tokens get rotated, not 'checked'. And one rule from now on: before 'trust' on a foreign project, you read exactly what's about to run.