VC
Value Add VC
⚡HomePulse⚡Helpful Apps📝Blog🤝Partner
Illustration for: NPM Worm Steals Credentials, Hits Claude Code Hooks
Value Add VC/Pulse/REGULATION

NPM Worm Steals Credentials, Hits Claude Code Hooks

A compromised maintainer account let attackers plant a credential-stealing worm across the keyv, cacheable and related npm packages -- some with 500M+ monthly downloads -- hitting Claude Code and VS Code hooks.

By the Numbers

2,234
Poisoned versions
444
Package names hit
09:35-13:18
Attack window (UTC)
~127M
keyv weekly downloads
TC
Trace Cohen
Early-stage VC & angel · Founder, New York Venture Partners
August 4, 2026
1 min read
ShareXLinkedInEmail
TC

The VC Read · Trace's Take

Trace Cohen

The detail that should worry every AI-coding-tool investor isn't the credential count, it's that this worm specifically targeted Claude Code and VS Code hooks -- attackers are now building for AI-agent dev environments as a named target, not an afterthought. If you're diligencing a dev-tools or AI-coding portfolio company, the question just changed from 'do you have SSO' to 'what happens when a transitive dependency four layers down gets a maintainer account compromised' -- because that's exactly what happened here to code nobody at the affected companies had ever heard of.

Analysis

A Maintainer Account, Not a Zero-Day

Attackers compromised the GitHub account of the maintainer behind keyv, a key-value caching library with roughly 127 million weekly npm downloads, and used that access to push a credential-stealing worm across keyv's entire package family, according to [The Hacker News](https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html). The same maintainer also owns cacheable, flat-cache and file-entry-cache -- some individually pulling more than 500 million downloads a month -- all swept into the same compromise.

“Twelve unrelated organizations were confirmed compromised within a roughly four-hour window on August 4, with 2,234 poisoned versions found across 444 package names.”

Every poisoned package received a preinstall hook that ran automatically on npm install, downloading the Bun runtime and executing a roughly 728 KB obfuscated stealer targeting .npmrc tokens, GitHub CLI tokens, AWS credentials, Vault tokens, Kubernetes configs and crypto wallets, per [Socket's](https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain) technical writeup. The worm also planted hooks targeting Claude Code and VS Code specifically -- a detail that makes this the first major supply-chain attack aimed explicitly at AI coding-agent environments rather than generic developer credentials. Twelve unrelated organizations were confirmed compromised within a roughly four-hour window on August 4, with 2,234 poisoned versions found across 444 package names.

This follows the same self-propagating pattern that hit npm earlier this year: one compromised maintainer account cascades into hundreds of downstream packages within hours, because modern JavaScript projects routinely depend on caching utilities several layers deep without anyone auditing them individually.

The counterweight worth noting: npm's ecosystem has had multiple worm-style incidents this year, and each one has been caught and contained within roughly a day -- this is a real, costly incident, not evidence the entire package ecosystem is unusable. What to watch: whether npm or GitHub ships mandatory hardware-key two-factor authentication for maintainers of packages above a download threshold, the structural fix security researchers have called for after every one of these incidents.

ShareXLinkedInEmail

More on

Anthropic →

Analysis and editorial commentary by Value Add Pulse.

← Back to Pulse

THE WIRE in your inbox— Tech, startup & VC news with Trace's take. Free, no spam.

Read Next

REGULATION· Aug 4, 2026

FCC Drafts Ban on Chinese Data Center Gear

Illustration for: FCC Drafts Ban on Chinese Data Center Gear
REGULATION

FCC Drafts Ban on Chinese Data Center Gear

The Trump administration is drafting an FCC ban on new Chinese-made data center components like optical transceivers, citing risks of data theft, malware and service disruption at US AI facilities.

REGULATION· Aug 5, 2026

Warren Grills Lutnick Over UAE Chip Export Rules

Illustration for: Warren Grills Lutnick Over UAE Chip Export Rules
REGULATION

Warren Grills Lutnick Over UAE Chip Export Rules

Senator Elizabeth Warren demanded Commerce Secretary Howard Lutnick explain why the administration eased export controls giving the UAE access to sensitive US tech, after UAE-linked entities invested in Trump-linked crypto ventures.

REGULATION· Aug 5, 2026

The 2026 Midterms Are Becoming the First AI Election

Illustration for: The 2026 Midterms Are Becoming the First AI Election
REGULATION

The 2026 Midterms Are Becoming the First AI Election

Axios reports campaigns are now using AI to generate persuasion content at scale and to poll simulated electorates, shifting AI from a disinformation worry to standard campaign infrastructure ahead of the midterms.

@Trace_Cohen·t@nyvp.com