// uncategorised

npm Supply Chain Worm Spreads to 868 Packages, 2 Billion Monthly Installs

An npm supply chain attack that started with a single compromised library, keyv, has spread to at least 868 packages carrying a combined total of more than two billion monthly installs.

The attack begins with a malicious preinstall hook planted in keyv that steals credentials the moment the package is installed: npm tokens, GitHub tokens, AWS keys, and more. Those stolen tokens are then used automatically to publish malicious updates to other packages the compromised maintainer or token can reach, which is how the worm spreads from one library to hundreds without a human attacker doing the propagation by hand. It is the same self-propagating shape security teams have now seen repeatedly in 2026, following the axios compromise in March (attributed to the suspected North Korean group UNC1069) and the node-ipc compromise in May, which harvested over 90 categories of credentials including cloud keys, SSH keys, and CI/CD secrets.

At the scale of 868 packages and billions of monthly installs, the realistic response is not “did we install the bad package,” it is “which of our dependencies, direct or transitive, touched this during the compromise window.” Lockfiles help identify exposure, but only if you actually pin versions and audit what update automation pulled in during the attack window, rather than trusting that a popular package is safe because it is popular.

This is the recurring lesson of 2026’s npm incidents: the trust boundary in modern software is the dependency tree, not the code you wrote yourself. Reviewing what that tree actually contains, and whether a compromised dependency could reach anything sensitive in your build pipeline, is what our secure code review covers.


// get started

Work with AgentOffense

Tell us about your target and goals. We’ll reply with scope and a fixed-price quote — usually within one business day.

./request_engagement