Sev0AI security incidents, tracked

All incidents / Manipulated AI

CHAINDROP npm worm planted persistence hooks in Claude Code settings

Multiple, disclosed 4 Aug 2026. Manipulated AI Data exposed High

A self-propagating worm starting from a hijacked maintainer account spread to 452 npm packages with around two billion monthly downloads. Alongside cloud and CI secrets it harvested AI tool configs and planted hooks in Claude Code and VS Code settings so it re-ran on every coding agent session.

Disclosed
4 Aug 2026
Organization
Multiple
Vendor
Multiple models
Product
Claude Code
Type of AI
Coding assistant
How it happened
Manipulated AI: Agent hijack
Harm
Data exposed
Data involved
Credentials
Reach
Ecosystem-wide
Severity
High
Model at fault
No
Status
Confirmed

Sources

  1. https://www.elastic.co/security-labs/shai-hulud-chaindrop-npm-supply-chain
  2. https://safedep.io/keyv-npm-supply-chain-compromise/

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "CHAINDROP npm worm planted persistence hooks in Claude Code settings", https://sev0.fyi/incidents/2026-08-04-chaindrop-npm-worm-claude-hooks/