Worm Attack Compromises Hundreds of Popular npm Packages
A significant security breach has occurred in the npm ecosystem, with a worm compromising hundreds of popular npm packages. The attack involved injecting a backdoor into packages such as 'keyv', 'file-entry-cache', and 'flat-cache', which collectively have over 150 million monthly downloads. The malicious payload is capable of spreading to adjacent npm packages, posing a widespread threat to software supply chains. The attack was identified on August 4, 2026, and is being actively investigated by security researchers.