generalnews.media
importance 4/5 Exclusive

npm Worm via Keyv Plants Backdoor in Hundreds of Packages

A malicious worm linked to the popular Keyv library has compromised hundreds of npm packages, injecting harmful hooks into Claude Code and VS Code development tools. The attack targets developers, potentially stealing credentials or planting persistent backdoors in their environments. This highlights the growing risk of supply chain attacks on open-source ecosystems.

Security

Sources (1)

security
← Back to home