PulseAugur
EN
LIVE 19:38:02

npm worm poisons packages with Claude and VS Code hooks

A malicious worm targeting the Node Package Manager (npm) has compromised hundreds of packages by injecting malicious code. This worm, linked to Keyv, has been observed planting code related to Claude and Visual Studio Code, potentially to steal sensitive information or disrupt development workflows. The ongoing nature of these attacks highlights persistent security vulnerabilities within the software supply chain. AI

IMPACT Highlights ongoing risks to the software supply chain, potentially impacting AI development tools and models.

RANK_REASON The item describes a security incident involving malicious code injection into software packages, which falls under the 'tool' category as it relates to software development tools and their vulnerabilities.

Read on Mastodon — mastodon.social →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

npm worm poisons packages with Claude and VS Code hooks

COVERAGE [1]

  1. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks https:// thehackernews.com/2026/08/keyv -linked-npm-worm-poisons-hundred

    Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks https:// thehackernews.com/2026/08/keyv -linked-npm-worm-poisons-hundreds.html https:// thehackernews.com/2026/08/keyv -linked-npm-worm-poisons-hundreds.html?m=1 Again… and again… and … # ai #…