npm Worm Outlives Token Rotation

A normal dependency install has turned into a self-spreading credential theft path. The standard fix of deleting one bad package and rotating tokens misses the real break: the malware can watch for revocation, leave hooks in developer tools, and keep running from trusted workspaces after the first account is cleaned up. The infection started with keyv@6.0.0 and then spread across the Keyv and Cacheable families, with reporting ranging from 353 poisoned versions across 79 package names to 440+ packages and 860+ packages overall. The payload runs at install time, steals cloud, CI, npm, GitHub, Vault, Kubernetes, and private-key material, republishes trojanized packages with stolen publishing access, and leaves Claude Code and VS Code hooks in place for developers who open the workspace. That makes the blast radius the developer and CI trust chain, not the original maintainer account. If the worm ran on a workstation or runner, the compromise can persist through local handlers and reused credentials long after the package itself is removed.

Part of the PlainSec briefing for 2026-08-05

Every edition of this story: npm Worm Outlives Token Rotation

Sources