TechWave AI Pulse Signal over noise
GOOD AI GLOBAL

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 pac

The Hacker News Tue, 04 Aug 2026 13:30
Read the original at The Hacker News ↗