npm Worm Targets AI Coding Agents via Editor Lifecycle Hooks
A newly identified npm worm, linked to the widely-used caching library Keyv, goes beyond typical credential theft by planting hooks inside AI coding tools such as Claude Code and VS Code. The malware exploits lifecycle events like folder-open and session-start triggers, executing malicious code the moment a developer trusts a workspace in their editor. Unlike traditional supply-chain attacks that rely on install-time scripts, this worm leverages developer habits and broad workspace trust grants as its detonation mechanism. Security researchers note the technique is not a novel AI exploit but rather a familiar npm script-abuse playbook applied to a new layer of automation tooling. The incident highlights a largely unaddressed gap: agent and editor hook systems have not received the same security scrutiny as CI pipelines, leaving transitive dependency chains exposed to this class of attack.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in