emerging threats and vulnerabilities

Worm compromises hundreds of popular npm packages

August 4, 2026

Worm Compromises Hundreds Of Popular Npm Packages

On August 4, 2026, several high-profile npm packages were compromised and used to propagate a backdoor. Commit 174f6a5 on the keyv npm package is an example of the malicious payload used as part of this campaign.

Some of the compromised packages are highly popular. For instance, keyv, file-entry-cache, and flat-cache each individually total 150 million monthly downloads. We believe the payload has the ability to spread to adjacent npm packages.

How to know if you're affected

While the situation is quickly evolving, we're publishing below a dynamic list of npm packages that were compromised as part of this campaign and distribute a malicious payload. You can access a CSV version on our GitHub repository.

Show the list of compromised npm packages

Loading latest data…

Developing situation

This is a developing situation and we'll publish an in-depth analysis of this campaign in the coming hours.

How Datadog can help

Datadog Code Security can identify hosts, containers, and build environments where the compromised version was installed. Refer to the in-app Security Research Feed card for more information.

Datadog also maintains the open source supply-chain security firewall (SCFW), which can proactively block known malicious packages at installation time. It can also log every single npm and PyPI package installed on a developer's workstation and ship it to your Datadog organization, allowing you to react when new malicious or compromised packages are discovered.

Did you find this article helpful?

Subscribe to the Datadog Security Digest

Get the latest insights from the cloud security community and Security Labs posts, delivered to your inbox monthly. No spam.

Related Content