VC
Value Add VC
⚡HomePulse⚡Helpful Apps📝Blog🤝Partner
Illustration for: NPM Worm Steals Credentials, Hits Claude Code Hooks
Value Add VC/Pulse/REGULATION

NPM Worm Steals Credentials, Hits Claude Code Hooks

A compromised maintainer account let attackers plant a credential-stealing worm across the keyv, cacheable and related npm packages -- some with 500M+ monthly downloads -- hitting Claude Code and VS Code hooks.

By the Numbers

2,234
Poisoned versions
444
Package names hit
09:35-13:18
Attack window (UTC)
~127M
keyv weekly downloads
TC
By the Markets Desk
Edited by Trace Cohen · Early-stage VC & angel · Founder, New York Venture Partners
August 4, 2026
1 min read
ShareXLinkedInEmail
TC

The VC Read · Trace's Take

Trace Cohen

The detail that should worry every AI-coding-tool investor isn't the credential count, it's that this worm specifically targeted Claude Code and VS Code hooks -- attackers are now building for AI-agent dev environments as a named target, not an afterthought. If you're diligencing a dev-tools or AI-coding portfolio company, the question just changed from 'do you have SSO' to 'what happens when a transitive dependency four layers down gets a maintainer account compromised' -- because that's exactly what happened here to code nobody at the affected companies had ever heard of.

Analysis

A Maintainer Account, Not a Zero-Day

Attackers compromised the GitHub account of the maintainer behind keyv, a key-value caching library with roughly 127 million weekly npm downloads, and used that access to push a credential-stealing worm across keyv's entire package family, according to The Hacker News. The same maintainer also owns cacheable, flat-cache and file-entry-cache -- some individually pulling more than 500 million downloads a month -- all swept into the same compromise.

“Twelve unrelated organizations were confirmed compromised within a roughly four-hour window on August 4, with 2,234 poisoned versions found across 444 package names.”

Every poisoned package received a preinstall hook that ran automatically on npm install, downloading the Bun runtime and executing a roughly 728 KB obfuscated stealer targeting .npmrc tokens, GitHub CLI tokens, AWS credentials, Vault tokens, Kubernetes configs and crypto wallets, per Socket's technical writeup. The worm also planted hooks targeting Claude Code and VS Code specifically -- a detail that makes this the first major supply-chain attack aimed explicitly at AI coding-agent environments rather than generic developer credentials. Twelve unrelated organizations were confirmed compromised within a roughly four-hour window on August 4, with 2,234 poisoned versions found across 444 package names.

This follows the same self-propagating pattern that hit npm earlier this year: one compromised maintainer account cascades into hundreds of downstream packages within hours, because modern JavaScript projects routinely depend on caching utilities several layers deep without anyone auditing them individually.

The counterweight worth noting: npm's ecosystem has had multiple worm-style incidents this year, and each one has been caught and contained within roughly a day -- this is a real, costly incident, not evidence the entire package ecosystem is unusable. What to watch: whether npm or GitHub ships mandatory hardware-key two-factor authentication for maintainers of packages above a download threshold, the structural fix security researchers have called for after every one of these incidents.

ShareXLinkedInEmail

More on

Anthropic →

Reported by The Hacker News · First reported by Socket · Analysis by Value Add Pulse.

← Back to Pulse

THE WIRE in your inbox— Tech, startup & VC news with Trace's take. Free, no spam.

Read Next

REGULATION· Aug 15, 2026

OpenAI Sets a Date for Ads to Hit ChatGPT in Europe

Illustration for: OpenAI Sets a Date for Ads to Hit ChatGPT in Europe
REGULATION

OpenAI Sets a Date for Ads to Hit ChatGPT in Europe

OpenAI notified Free and Go users across the EEA and Switzerland that ads will begin appearing in ChatGPT later this month, the first formal European rollout timeline since ads expanded to five other countries in August.

REGULATION· Aug 14, 2026

Apple Proposes 15% Cut on Purchases Outside App Store

Illustration for: Apple Proposes 15% Cut on Purchases Outside App Store
REGULATION15% commission

Apple Proposes 15% Cut on Purchases Outside App Store

Apple asked a federal judge to let it charge up to 15% on purchases made through external links inside iOS apps, a court-ordered concession in its long-running Epic Games fight that developers say still falls short of a truly open App Store.

REGULATION· Aug 13, 2026

Tether Finally Gets Its Big Four Audit -- and a $6.8B Surplus

Illustration for: Tether Finally Gets Its Big Four Audit -- and a $6.8B Surplus
REGULATION$6.8B reserve surplus

Tether Finally Gets Its Big Four Audit -- and a $6.8B Surplus

KPMG completed the first independent Big Four audit of Tether's reserves, confirming a $6.8 billion surplus over liabilities and $141 billion in US Treasury holdings behind the $183 billion USDT stablecoin.

@Trace_Cohen·t@nyvp.com