๐จ npm ๊ณต๊ธ๋ง ๊ณต๊ฒฉ ๋ฐ์: ๊ฐ๋ฐ์ ์๊ฒฉ ์ฆ๋ช ์ ํ์ทจํ๊ณ Claude Code ๋ฐ VS Code ํ๊ฒฝ์ ๋ ธ๋ฆฌ๋ ์ ๐จ
๐จ Active npm supply-chain worm is stealing developer credentials and targeting Claude Code / VS Code environments ๐จ
ํต์ฌ ์์ฝ
npm ํจํค์ง 'keyv'์ 'cacheable'์ ํฌํจํ ๊ณต๊ธ๋ง ๊ณต๊ฒฉ์ด ๋ฐ์ํ์ฌ ๊ฐ๋ฐ์ ์๊ฒฉ ์ฆ๋ช ํ์ทจ ๋ฐ AI ์ฝ๋ฉ ๋๊ตฌ ํ๊ฒฝ์ ๊ฐ์ผ์ํค๊ณ ์์ต๋๋ค.
- ๊ณต๊ธ๋ง ๊ณต๊ฒฉ โ keyv ๋ฐ cacheable ํจํค์ง๊ตฐ์ ํตํด ์ ์ฑ ์ฝ๋๊ฐ ํ์ฐ๋จ
- ์๊ฒฉ ์ฆ๋ช ํ์ทจ โ npm, GitHub, AWS, GCP ๋ฑ ๋ค์ํ ๊ฐ๋ฐ์ ํ ํฐ๊ณผ ํค๋ฅผ ํ์ทจํจ
- AI ๋๊ตฌ ํ๊ฒํ โ Claude Code์ VS Code์ ์ค์ ํ์ผ์ ์ด์ฉํด ์๋ ์คํ๋จ
- ๋์ ๋ฐฉ์ โ npm ์ค์น ์ --ignore-scripts ์ต์ ์ฌ์ฉ ๋ฐ ์๊ฒฉ ์ฆ๋ช ์ฆ์ ๊ต์ฒด ํ์
Active npm supply-chain worm is stealing developer credentials and targeting Claude Code / VS Code environments
Socket Security is tracking an active npm supply-chain attack discovered on August 4, 2026. It initially affected the widely used keyv and cacheable package families and has since spread to packages belonging to other maintainers.
The affected packages collectively receive tens of millions of downloads per week and are often buried deep inside dependency trees, meaning developers may have them installed without knowingly adding them. One example dependency path is:
eslint โ file-entry-cache โ flat-cache โ keyv
At the time Iโm posting this, Socketโs live tracker lists 2,236 affected package artifacts across 444 unique packages. That number may continue changing because this is an active, self-propagating campaign.
What the malware does
The compromised packages contain a malicious preinstall hook:
json "preinstall": "node setup.mjs"
When an affected package is installed with lifecycle scripts enabled, setup.mjs downloads a standalone Bun runtime and uses it to execute an obfuscated payload named Math_Symbol.js.
The packageโs normal library code may still function correctly afterward, so the installation can appear successful even though the system has already been compromised.
The payload searches for and steals credentials including:
- npm publishing tokens
- GitHub tokens and CI credentials
- AWS credentials and instance metadata
- GCP service-account keys
- Azure client secrets
- HashiCorp Vault tokens
- Kubernetes service-account tokens
- Private keys, bearer tokens and other secrets found in files, environment variables or running processes
The stolen information is encrypted and exfiltrated through attacker-controlled GitHub repositories and destinations resolved through DNS.


