NPM worm in Keyv: credential theft and VS Code hooks
A credential-stealing NPM worm in Keyv spread beyond the original namespace and poisoned hundreds of npm packages. It also planted editor hooks that can trigger the payload when a workspace is trusted.