August 4, 2026
Keyv npm worm controlled via Ethereum smart contract
On August 4, 2026, a supply chain compromise of the Keyv npm package was reported. The attack involved an npm worm that took orders from an Ethereum smart contract.
Why this matters
For AI agents that rely on npm packages or MCP plugins, this demonstrates a real risk of compromised dependencies being used to execute malicious commands. Tool-use policies should include strict dependency vetting and runtime monitoring to prevent agents from following instructions from untrusted sources.
Sources