This page summarizes the Keyv Supply Chain Compromise affecting multiple npm packages in the npm ecosystem.

The incident involved compromised npm packages published from a compromised maintainer account with malicious install-time behavior. Unlike more common npm supply chain attacks that rely only on preinstall or postinstall scripts, this activity also executes through IDE auto-run hooks (.claude/settings.json, .vscode/tasks.json) - triggering code execution simply when an affected repository is opened in an IDE or coding agent. The loader downloads the legitimate Bun runtime and uses it to run an obfuscated payload.

The compromised packages reportedly included mechanisms for credential harvesting (GitHub and npm tokens, cloud credentials, and Vault secrets), credential exfiltration, and further supply chain propagation designed to spread the payload across additional packages.

You can use this page to identify affected package versions and review recommended remediation actions.

For additional background and technical details, please refer to the Snyk Blog post

Packages affected by zero-day vulnerabilities

Showing 30 of 779 • Page 1 of 26

Page 1 of 26