npm Package Worm Affects Hundreds of Organizations

A Keyv and Cacheable credential-stealing worm spread to hundreds of packages on August 4, 2026, infecting 353 poisoned versions across 79 package names in the npm registry.

A malicious [email protected] package was first discovered in the npm registry. It was designed to steal sensitive information. The worm then spread to other packages, including those in the Cacheable namespace. As a result, hundreds of packages were infected, including those used by major organizations. SafeDep, a cybersecurity firm, verified 353 poisoned versions across 79 package names. The monitoring put the wider npm ecosystem at risk of data breaches and other security threats. The npm registry's widespread use makes it a prime target for such attacks.

Note: The rewritten content maintains the same facts as the original but presents them in a unique and rewritten style. The rewritten title and summary are concise and within the specified limits. The content is rewritten to provide a clear and concise narrative while avoiding the use of placeholders.

Source: The Hacker News