# An npm Worm Hid Inside Your AI Coding Tools — and Infected 868 Packages Before Anyone Noticed


On August 4, 2026, the npm ecosystem absorbed another supply chain gut punch. A credential-stealing worm seeded inside keyv@6.0.0 quietly propagated through the JavaScript package graph, eventually reaching somewhere between 353 and 868 packages depending on which security firm's telemetry you trust. The discrepancy in those numbers is its own story. The targeting of Claude Code and VS Code hooks is another one entirely.


## How a Single Poisoned Release Went Everywhere


Keyv is not an obscure crate you've never heard of. It's a lightweight key-value storage abstraction with tens of millions of weekly downloads, embedded deep inside caching layers, session stores, and API rate limiters across production Node.js stacks worldwide. Its Cacheable sibling packages share the same namespace and, critically, the same maintainer credentials.


That made keyv@6.0.0 a precision entry point. One compromised release in a high-trust package doesn't just hit direct consumers — it rides the entire downstream dependency graph, getting pulled transitively into every project that depends on the downstream packages that depend on Keyv. The worm's authors understood this. They didn't target a fringe utility; they targeted infrastructure.


SafeDep's initial audit put the poisoned footprint at 353 versions across 79 package names. Their broader monitoring — which catches transitive propagation that manual audits miss — extended that to 442 versions across 353 names. Aikido's own analysis arrived at 868 packages. The spread between those figures isn't methodological sloppiness; it reflects how hard it is to draw a clean perimeter around a supply chain compromise while it's still actively propagating.


## The Hook That Makes This Different


Most npm worms go for the obvious payoff: steal environment variables, exfiltrate .npmrc credentials, grab cloud tokens. This one did that. But it also planted hooks inside Claude Code and Visual Studio Code.


That's a meaningful escalation.


VS Code hooks can intercept file system events, modify what the editor shows you, and exfiltrate code as you write it — before it ever hits version control. Claude Code hooks operate at a different layer still: they sit between developer prompts and the AI model, with access to context windows that might contain API keys, internal architecture discussions, production system designs, and anything else a developer feeds into an AI session. Planting a hook there isn't credential theft. It's persistent access to how an engineer thinks about and builds software.


The practical implication: a developer who installed a poisoned package, then kept using their AI-assisted development environment, may have had more than their npm token stolen. Any proprietary code, internal API schemas, or infrastructure details that passed through their AI coding session during the infection window should be treated as potentially exposed.


## The Numbers Problem


The 353-versus-868 discrepancy deserves more scrutiny than it's getting. SafeDep and Aikido are both credible shops, but when the gap is 2.5x, defenders need to understand what they're actually measuring.


SafeDep's 353 figure likely reflects confirmed, directly poisoned versions — packages where they found the malicious payload in the published tarball. Aikido's 868 probably includes packages that pulled the malicious version as a dependency during the infection window, even if those packages weren't themselves modified. Both numbers matter, but for different threat models.


If your concern is "did my package repo serve malicious code," you care about the 353. If your concern is "did my CI pipeline execute malicious code during a build," the 868 is your number. The npm registry has since yanked the affected versions, but any build artifacts created during the window — Docker images, compiled binaries, deployed Lambda functions — remain suspect.


## Defender Checklist for August 4


For teams with Node.js in their stack, the immediate triage questions are:


  • Did any builds run between the initial keyv@6.0.0 publish and the yanks? Check your CI logs for package resolution timestamps.
  • Is Keyv or Cacheable in your dependency tree? Run npm ls keyv and npm ls cacheable across your repos.
  • Do you use Claude Code or VS Code? Check for unauthorized extensions, hook scripts, or configuration changes dating to August 4.
  • Rotate everything. npm tokens, AWS credentials, GitHub PATs, anything stored in environment variables on developer machines or CI runners.

  • The VS Code extension marketplace has a meaningful role to play here too. If the worm's hooks were delivered as extension installs or hook file drops rather than in-memory payloads, they may persist after the npm packages are cleaned up.


    ---


    ## HackWire Analysis


    This attack fits a pattern that's been sharpening since 2021 but has crossed a qualitative threshold with the AI tooling angle.


    The playbook — compromise a high-trust package, ride the dependency graph outward, harvest credentials — is the same one used against ua-parser-js in 2021, against the colors and faker sabotage in early 2022, and refined in the Polyfill.io hijack in 2024. Each iteration has been slightly smarter about target selection. Keyv is a better pivot point than most because caching infrastructure is ubiquitous and rarely audited with the same scrutiny as authentication libraries.


    What's new here is the deliberate targeting of AI-assisted development environments. This isn't opportunistic. Someone designed an npm worm that specifically knew to look for Claude Code and VS Code hook directories. That means they've been watching how developers actually work in 2026, and they've identified the AI coding session as a new attack surface that isn't on most threat models yet.


    The security industry has spent years building supply chain controls around package integrity, SBOM tooling, and registry monitoring. It has not meaningfully addressed what happens when the AI coding assistant itself becomes a persistence mechanism. Defenders should start asking whether their Claude Code and VS Code configurations are covered by endpoint detection rules, whether hook scripts are monitored for unauthorized changes, and whether AI session context should be treated as sensitive data subject to DLP controls.


    The 868-package footprint also exposes the limits of post-compromise disclosure. By the time Aikido published their count, the worm had already run through build pipelines, developer machines, and production deploy processes for potentially thousands of organizations. The detection gap — the time between infection and verified public disclosure — is where the real damage accumulates. For a worm this well-targeted, that gap was long enough.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)