A malicious worm has compromised hundreds of npm packages by exploiting the popular Keyv library, injecting code that installs hooks into Claude Code and VS Code editors to potentially capture sensitive data or inject malicious commands. Organizations sho
Read the full article: https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html