Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
npm Worm Targets Hundreds of Packages with Credential Theft

npm Worm Targets Hundreds of Packages with Credential Theft

Posted on August 4, 2026 By CWS

A recently discovered npm worm has infiltrated hundreds of software packages, originating from [email protected] and spreading across various namespaces. This malicious activity was first observed on August 4, 2026, impacting multiple organizations and posing significant security risks.

Widespread Impact and Initial Findings

SafeDep identified 353 compromised versions among 79 package names within the npm registry. Their monitoring indicated a broader impact, with 442 versions across 353 names affected. Aikido later reported an even larger footprint, with at least 868 packages involved across 1,381 versions. However, these broader numbers could not be independently verified from public lists by the reporting deadline.

The worm utilizes a preinstall script to execute a credential-stealing bundle in developer environments, capable of extracting repository and package registry credentials. This allows the worm to propagate by exploiting npm publishing access to infect additional packages.

Technical Mechanisms and Propagation

The Keyv repository also carries hooks for Claude Code and Visual Studio Code (VS Code), which can trigger the malicious payload under certain conditions. According to Socket, any environment running an affected version should be treated as compromised, with organizations advised to remove the malware’s credential-revocation watcher before rotating exposed tokens.

Security measures in npm 12, which block unapproved dependency lifecycle scripts, offer some protection. However, earlier npm versions remain vulnerable, allowing lifecycle scripts to be executed unnoticed.

Analysis and Consequences

The initial malicious release, [email protected], introduced a preinstall command and included additional files for malicious purposes. The stage one payload specifically checks for Bun and downloads a specific version from GitHub if necessary, executing a large compiled bundle to harvest sensitive information.

SafeDep’s analysis of the payload reveals its capability to extract data from GitHub, npm, cloud services, and other key infrastructures. The worm further includes code for modifying and republishing packages under stolen npm identities.

Security Recommendations and Future Outlook

The rapid changes in the registry complicate efforts to maintain a comprehensive list of affected packages. As such, security checks should rely on exact package names and specific resolved versions rather than cached tags.

Although not every package linked to the original maintainer was affected, the risk remains substantial. SafeDep recommends vigilance in monitoring for compromised credentials and emphasizes the importance of securing publishing accounts.

The connection between this attack and previous incidents, such as the April compromise of the lightning PyPI package, suggests a possible link within a broader malware family. However, the identity of those responsible remains unknown, highlighting the growing complexity and sophistication of modern cyber threats.

The Hacker News Tags:Claude Code, credential theft, Cybersecurity, GitHub, Keyv, Malware, npm worm, SafeDep, Socket, VS Code

Post navigation

Previous Post: Cybercriminals Exploit AI for Sophisticated Scams
Next Post: Oligo Secures $60M to Enhance Runtime Security

Related Posts

Android 17 Enhances Security by Limiting Accessibility API Access Android 17 Enhances Security by Limiting Accessibility API Access The Hacker News
What 2025 Is Teaching Us About Cloud Defense What 2025 Is Teaching Us About Cloud Defense The Hacker News
North Korea-Linked UNC1069 Targets Crypto with AI Attacks North Korea-Linked UNC1069 Targets Crypto with AI Attacks The Hacker News
Enhancing Mobile Security with Samsung Knox Enhancing Mobile Security with Samsung Knox The Hacker News
Critical Security Updates Released for Major Software Critical Security Updates Released for Major Software The Hacker News
Google Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens Millions Google Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens Millions The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • DarkSword iOS Exploit Impacts 180 Websites and 27 Servers
  • CISO Insights: Russ Kirby on Passion and Leadership
  • Cyber Attacks Leverage Fake Software Updates for Remote Access
  • Six RCE Vulnerabilities Threaten AI Workflow Servers
  • Oligo Secures $60M to Enhance Runtime Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • DarkSword iOS Exploit Impacts 180 Websites and 27 Servers
  • CISO Insights: Russ Kirby on Passion and Leadership
  • Cyber Attacks Leverage Fake Software Updates for Remote Access
  • Six RCE Vulnerabilities Threaten AI Workflow Servers
  • Oligo Secures $60M to Enhance Runtime Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark