Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
npm Worm Targets Hundreds of Packages with Credential Theft

npm Worm Targets Hundreds of Packages with Credential Theft

Posted on August 4, 2026 By CWS

A recently discovered npm worm has infiltrated hundreds of software packages, originating from [email protected] and spreading across various namespaces. This malicious activity was first observed on August 4, 2026, impacting multiple organizations and posing significant security risks.

Widespread Impact and Initial Findings

SafeDep identified 353 compromised versions among 79 package names within the npm registry. Their monitoring indicated a broader impact, with 442 versions across 353 names affected. Aikido later reported an even larger footprint, with at least 868 packages involved across 1,381 versions. However, these broader numbers could not be independently verified from public lists by the reporting deadline.

The worm utilizes a preinstall script to execute a credential-stealing bundle in developer environments, capable of extracting repository and package registry credentials. This allows the worm to propagate by exploiting npm publishing access to infect additional packages.

Technical Mechanisms and Propagation

The Keyv repository also carries hooks for Claude Code and Visual Studio Code (VS Code), which can trigger the malicious payload under certain conditions. According to Socket, any environment running an affected version should be treated as compromised, with organizations advised to remove the malware’s credential-revocation watcher before rotating exposed tokens.

Security measures in npm 12, which block unapproved dependency lifecycle scripts, offer some protection. However, earlier npm versions remain vulnerable, allowing lifecycle scripts to be executed unnoticed.

Analysis and Consequences

The initial malicious release, [email protected], introduced a preinstall command and included additional files for malicious purposes. The stage one payload specifically checks for Bun and downloads a specific version from GitHub if necessary, executing a large compiled bundle to harvest sensitive information.

SafeDep’s analysis of the payload reveals its capability to extract data from GitHub, npm, cloud services, and other key infrastructures. The worm further includes code for modifying and republishing packages under stolen npm identities.

Security Recommendations and Future Outlook

The rapid changes in the registry complicate efforts to maintain a comprehensive list of affected packages. As such, security checks should rely on exact package names and specific resolved versions rather than cached tags.

Although not every package linked to the original maintainer was affected, the risk remains substantial. SafeDep recommends vigilance in monitoring for compromised credentials and emphasizes the importance of securing publishing accounts.

The connection between this attack and previous incidents, such as the April compromise of the lightning PyPI package, suggests a possible link within a broader malware family. However, the identity of those responsible remains unknown, highlighting the growing complexity and sophistication of modern cyber threats.

The Hacker News Tags:Claude Code, credential theft, Cybersecurity, GitHub, Keyv, Malware, npm worm, SafeDep, Socket, VS Code

Post navigation

Previous Post: Cybercriminals Exploit AI for Sophisticated Scams
Next Post: Oligo Secures $60M to Enhance Runtime Security

Related Posts

Malware Chain Exploits Blogger to Deploy PureLogs Stealer Malware Chain Exploits Blogger to Deploy PureLogs Stealer The Hacker News
Cross-Platform QuimaRAT MaaS Targets Multiple OS Cross-Platform QuimaRAT MaaS Targets Multiple OS The Hacker News
Two Distinct Botnets Exploit Wazuh Server Vulnerability to Launch Mirai-Based Attacks Two Distinct Botnets Exploit Wazuh Server Vulnerability to Launch Mirai-Based Attacks The Hacker News
AI Agent Security: From Visibility to Enforcement AI Agent Security: From Visibility to Enforcement The Hacker News
Fortinet Warns About FortiSIEM Vulnerability (CVE-2025-25256) With In-the-Wild Exploit Code Fortinet Warns About FortiSIEM Vulnerability (CVE-2025-25256) With In-the-Wild Exploit Code The Hacker News
SilentSync RAT Delivered via Two Malicious PyPI Packages Targeting Python Developers SilentSync RAT Delivered via Two Malicious PyPI Packages Targeting Python Developers The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Six RCE Vulnerabilities Threaten AI Workflow Servers
  • Oligo Secures $60M to Enhance Runtime Security
  • npm Worm Targets Hundreds of Packages with Credential Theft
  • Cybercriminals Exploit AI for Sophisticated Scams
  • AI Chatbots’ Vulnerability to Account Hijacking Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Six RCE Vulnerabilities Threaten AI Workflow Servers
  • Oligo Secures $60M to Enhance Runtime Security
  • npm Worm Targets Hundreds of Packages with Credential Theft
  • Cybercriminals Exploit AI for Sophisticated Scams
  • AI Chatbots’ Vulnerability to Account Hijacking Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark