npm supply-chain worm steals credentials, targets Claude Code environments

SaiyanOfDarkness · reddit · 2026-08-05

Security firm Socket is tracking an active npm supply-chain worm. Initially infecting the popular keyv and cacheable packages, it has spread to hundreds of others via self-propagation. The malware uses a malicious preinstall hook to deploy an obfuscated payload that specifically harvests developer credentials like npm, GitHub, and AWS tokens.

Worm-like Propagation & AI Targeting

The malware also installs a persistence mechanism on macOS and Linux, requiring thorough environment cleanup before rotating credentials.

Related event: npm Ecosystem Hit by Supply Chain Worm Infecting 868+ Packages(5 posts)→

Original post →

More from coding & agent

coding & agent channel →