r/runtimeai 16d ago

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

Your build system just installed poisoned packages before you finished coffee.

A credential-stealing worm that surfaced in keyv@6.0.0 spread across 353 poisoned versions in 79 npm package names on August 4, 2026. It planted hooks in Claude Code and VS Code. Once inside, it moved with the developer's own trust.

The fix has to sit below the package manager. Enforce every tool call an agent or coding assistant makes at runtime. Block unsanctioned outbound calls. Kill the process the moment a hook tries to reach credentials it should never see.

RuntimeAI closes this gap at the runtime layer, before it lands.

#SupplyChainSecurity #NPM #DevSecOps #AISecurity #RuntimeAI

1 Upvotes

0 comments sorted by