we_are_coded.by CODE · The world, decoded
БГ
Supply chain

A worm took over keyv and hundreds of npm packages - and plants hooks in Claude Code and VS Code

Datadog Security LabsSecurity

On 4 August a poisoned version of keyv started spreading through npm - it steals tokens and keys, republishes itself under someone else's name, and plants hidden commands. Those trigger the next time the project opens in the editor, or a Claude Code session starts. The signatures were valid: the source was poisoned before the build.

In short
  • A hijacked maintainer account published poisoned keyv@6.0.0 (04.08, 09:35 UTC); the worm spreads using stolen npm tokens and, per Datadog's analysis, reaches hundreds of packages.
  • The payload steals SSH keys, GitHub and npm tokens, and cloud credentials - and plants hooks in .claude/settings.json and .vscode/tasks.json that run it again when the project opens.
  • The poisoned versions carry valid npm provenance attestation. Defense: npm install with --ignore-scripts, pinning clean versions, reviewing .claude/ and .vscode/, rotating tokens.
Checked on5 August 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

If npm install ran anywhere in the world yesterday, there's a real chance that machine is already leaking keys to a foreign server. Open the project afterward with Claude Code or VS Code, and the infection has left a backup entry - a backdoor - too.

The facts: on 4 August between 09:02 and 09:35 UTC, attackers with a hijacked maintainer account publish poisoned keyv@6.0.0 - a package with over 150 million weekly downloads, per Datadog. By 10:28, nine more packages from the Cacheable family are poisoned (cacheable, flat-cache, file-entry-cache, cache-manager and others), and the total number of affected packages per Datadog Security Labs' analysis is in the hundreds. The worm spreads itself: it steals npm tokens, some with the right to bypass 2FA, and uses them to publish poisoned versions under someone else's name. A hidden preinstall script pulls a payload that collects SSH keys, GitHub and npm tokens, cloud credentials and secrets from Kubernetes. It also plants hooks in the repo itself: .claude/settings.json with a SessionStart command, and .vscode/tasks.json with a folder-open task - both run setup.mjs scripts from the repo on the next work session. The poisoned versions carried valid npm provenance attestation, because the legitimate build process signed code that was already poisoned. There's no CVE number - this isn't a code flaw, it's a hijacked account and a live operation. Researchers tie it, by the message in the code, to the Shai-Hulud worm: 'Here We Go Again'. Sources: Datadog Security Labs and Snyk, 04.08.2026.

Here's what isn't obvious at first glance: the attacker is now counting agents as a door too. The hook in .claude/settings.json waits for the exact moment a person or an agent says 'I trust this folder'. Until now the supply chain went after CI servers and developer laptops. This attack goes after the AI assistant's settings too - because it knows trust gets handed out there with one keystroke, and afterward nobody looks at what's actually written inside.

The second uncomfortable truth is the attestation. The release is signed, with valid provenance, passing every green check - because the source code it's built from was already poisoned. The signature guarantees who assembled the package and which shelf it came from. What's inside it, it never promised.

'Trust this workspace' is the key this attack is waiting for.

We run npm install with the --ignore-scripts flag while the dust settles. Versions get pinned. For keyv that's 5.6.0. In every repo touched these days, .claude/ and .vscode/ get reviewed line by line. GitHub and npm tokens get rotated, not 'checked'. And one rule from now on: before 'trust' on a foreign project, you read exactly what's about to run.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→Datadog Security Labs - Worm compromises hundreds of popular npm packages, 04.08.2026→Snyk - Inside the keyv npm Supply Chain Compromise, 04.08.2026
Original: https://wearecoded.com/en/articles/npm-chervei-keyv-kuki-v-claude-code.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news