An advanced credential-stealing npm malware surfaced in keyv@6.0.0, subsequently infecting numerous packages from various organizations on August 4, 2026 This article explores versions keyv repository. . Its monitoring revealed that this spanned an additional 442 versions across 353 distinct names, with Aikido later estimating at least 868 packages spanning 1,381 versions.

The Keyv repository also retained separate Claude Code and Visual Studio Code (VS Code) hooks that execute the payload upon user trust in the workspace or project configuration permission. Stage one checks for Bun, downloading version 1.3.13 from the runtime's official GitHub releases if necessary, then handing off to a 727,680-byte compiled bundle.

IST on August 4, npm pages for several packages showed earlier releases as being tagged "latest." Specifically, keyv@5.6.0, flat-cache@6.1.23, and cache-manager@7.2.9 were among the nine affected by this change. The full campaign could not be independently mapped package by package, so exposure checks must use exact package names, versions, and lockfiles instead of relying on a cached list of current tags.

The poisoned Keyv release included valid OpenID Connect (OIDC) and Supply-chain Levels for Software Artifacts (SLSA) provenance due to its successful passage through the project's legitimate GitHub Actions release workflow. The evidence indicates that the worm propagated independently of any compromised publishing identities and separate publisher credentials, rendering the package insufficient to determine the number of accounts that were affected.