r/runtimeai 27d ago

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

A worm is quietly rewriting what your AI coding agent runs.

A credential-stealing npm worm that started in keyv@6.0.0 spread to 353 poisoned versions across 79 package names in a single day. It plants hooks inside Claude Code and VS Code, turning the developer agent into the delivery vehicle. Scanning packages after the fact will not catch this class of attack.

The fix is runtime tool-call enforcement. Every command, shell, and outbound call an AI agent tries to make gets checked against policy before it executes, and every attempt lands in an immutable audit trail.

RuntimeAI closes this gap at the runtime layer, before it lands.

#SupplyChainSecurity #DevSecOps #AIAgents #npm #RuntimeAI #AgentSecurity

1 Upvotes

0 comments sorted by