The popular key-value database keyv and other widely used npm packages were targeted in a supply chain attack. The potential damage is significant.

A Keyv-linked npm worm poisoned 353 versions across 79 package names, stealing developer and CI credentials while repository hooks remained present.

Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry.