Install-Time-Execution
Keyv npm Worm Hits 800+ Packages, Pulls C2 From an Ethereum Smart Contract
A compromised [email protected] release triggered a self-propagating npm worm that poisoned 800+ packages in hours, planting Claude Code and VS Code persistence hooks and fetching C2 addresses via live Ethereum smart-contract calls.