datadog-security-labs · Crawled Aug 4, 2026
Worm compromises hundreds of popular npm packages
4 IoCs
Read original article ↗
AI Summary
On August 4, 2026, a worm compromised several high-profile npm packages, including keyv, file-entry-cache, and flat-cache, each with around 150 million monthly downloads. The malicious commit (174f6a5) in the keyv package introduced a backdoor designed to propagate to adjacent npm packages, indicating a supply chain attack aimed at widespread distribution. The campaign represents a significant open-source software supply chain compromise with potential for broad impact due to the popularity of the affected packages.
AI-extracted · verify before operational use