npm 웜 Keyv-Linked가 수백 개 패키지를 감염시킨 사건.
Keyv@6.0.0에서 시작된 npm 웜이 2026년 8월 4일에 Keyv 및 Cacheable 네임스페이스를 넘어 수백 개의 패키지로 퍼져나갔습니다. SafeDep는 npm 레지스트리에서 79개의 패키지 이름에 걸쳐 353개의 감염된 버전을 확인했습니다. 이후 Aikido에 의해 최소 868개의 패키지가 보고되었습니다.
The Keyv-Linked npm worm infected hundreds of packages.
The npm worm that started from keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages on August 4, 2026. SafeDep identified 353 poisoned versions across 79 package names in the npm registry. Additionally, Aikido later reported at least 868 infected packages.