npm Worm Now Spreads Through Stolen Tokens

The danger is no longer one bad maintainer account. Stolen npm and GitHub tokens now let the payload publish its own next wave, so cleaning one package or rotating one key can feed the spread instead of stopping it. The malicious release runs during npm install, and related hooks can also fire when a repo is opened in common developer tools. Reporting now puts the campaign at more than 2,200 malicious releases across about 440 packages, with keyv, cacheable, flat-cache, file-entry-cache, and cache-manager among the affected names. The worm steals developer and CI secrets, then uses those same credentials to backdoor more packages and repositories through trusted publishing paths. That changes containment. If infected workstations, build runners, or repos are still able to use stolen credentials, the worm can rearm itself and keep moving through npm and GitHub workflows.

Part of the PlainSec briefing for 2026-08-06

Editions

Sources