PulseAugur
EN
LIVE 15:58:49

NPM Worm Infects 637 Packages in 39 Minutes, Targets Dev Tools

A sophisticated worm infected 637 npm packages within 39 minutes on May 19, 2026, affecting approximately 16 million weekly downloads. The malware, originating from a compromised npm account, not only exfiltrated credentials from cloud environments and developer tools but also exploited GitHub Actions to gain further npm publish access, enabling self-propagation. Notably, the attack targeted developer environments by installing hooks in tools like Claude Code and VS Code, and included a dead man's switch to delete user files if stolen tokens were revoked. AI

IMPACT This attack highlights the evolving threat landscape for AI development tools and the software supply chain.

RANK_REASON This is a report of a malware attack targeting developer tools and packages, not a new model release or core AI research.

Read on dev.to — Claude Code tag →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

COVERAGE [1]

  1. dev.to — Claude Code tag TIER_1 English(EN) · Pico ·

    637 npm Packages Compromised in 39 Minutes. The Malware Installs a Claude Code SessionStart Hook.

    <p>On May 19, 2026, between 01:39 and 02:18 UTC, a single compromised npm account published 637 malicious package versions across 323 packages. The entire attack took 39 minutes.</p> <p>The packages included <code>jest-canvas-mock</code> (2.8M weekly downloads), <code>echarts-for…