Credential-Stealing Worm Spreads Across npm Packages

A worm targeting npm packages has affected hundreds of software components, raising security concerns for developers.

ThreatVectr Newsdesk· 2 min read
Photoreal news-editorial style, 16:9 framing, edge-to-edge composition
Share

Key points

  • Credential-stealing worm spread across 868 npm packages by August 4, 2026.
  • SafeDep verified 353 poisoned versions among 79 package names.
  • Aikido reported the worm's presence in at least 868 packages.

What happened with the npm packages?

A credential-stealing worm, first appearing in the npm package keyv@6.0.0, has spread across many npm packages. On August 4, 2026, it extended beyond the Keyv and Cacheable namespaces, affecting hundreds of software components. SafeDep, a company that monitors software supply chain security, identified that 353 versions across 79 package names in the npm registry were tainted. Aikido, another security firm, later reported the worm had infected at least 868 packages.

Should developers be worried?

Developers who use npm packages should be cautious. The worm's reach into 868 packages means that any software relying on these packages could be at risk of credential theft. This can lead to unauthorized access to systems and data breaches. Developers should check the integrity of their dependencies and update any compromised packages promptly. They should also monitor for any unusual activity in their systems that might indicate a breach.

How can developers protect their projects?

To protect their projects, developers need to ensure their packages are sourced from trusted repositories and regularly updated to the latest safe versions. They should also employ security tools that can detect and alert on suspicious code changes or package updates. SafeDep and Aikido's findings underscore the importance of continuous monitoring and verification to maintain the security of software supply chains.

© 2026 Threat Vectr