How the keyv npm attack reached VS Code and Claude Code

A poisoned `keyv@6.0.0` release published at 09:35 UTC on 4 August 2026 spread to over 400 npm package names within about 30 minutes.

The malicious versions carried valid npm attestation and GitHub Actions trusted-publisher credentials, so provenance checks did not flag them.

Beyond harvesting credentials, the payload planted persistence hooks in VS Code and Claude Code that fire when a developer trusts the workspace.

Read the full post

Read the full post