Realtime AI News
keyv npm supply chain attack hides malware in AI agent files scanners never read
A supply chain attack on the keyv npm package has been uncovered, with malware hidden in AI agent files that security scanners never read, Tech Times reports. The technique exploits a blind spot in automated scanning to slip malicious code into the npm ecosystem.

A supply chain attack targeting the keyv package on the npm registry has been uncovered, with malware concealed in AI agent files that automated security scanners never read, Tech Times reports.
The attack exploits a specific blind spot: the malicious payload is placed in file types associated with AI agents that scanners routinely skip.
Because the malware lives outside the scope of typical scanning, the infection can spread through the dependency chain without triggering standard alerts.
The incident is the latest reminder that the JavaScript package ecosystem remains an attractive target for attackers seeking to compromise many projects at once through a single dependency.
AI agent files are a notable wrinkle: as AI coding assistants and agent tooling proliferate, attackers are adapting to hide code in the files those tools and their scanners overlook.
For teams that use keyv or depend on it transitively, auditing dependency trees and scanning the file types automated tools skip is a sensible first step.
What to watch next: whether the malicious versions have been removed from the registry, how many downstream projects are affected, and whether scanner vendors extend coverage to AI agent file types.
Why it matters
A fresh npm supply chain incident hides malware in AI agent files to dodge automated scanners, exposing a new security blind spot as agent tooling spreads.
Nearby Updates
All08/05, 21:00
Benchmark Gensuite Launches MCP Connector to Give AI Agents Access to Enterprise Operational Risk Management
Benchmark Gensuite has announced an MCP connector that gives AI agents access to enterprise operational risk management data and workflows. The move aligns with the Model Context Protocol's rise as the standard for connecting agents to enterprise data, potentially embedding risk and compliance processes deeper into corporate AI operations.
08/05, 20:28
MacPaw taps Liquid AI to bring on-device inference to its app store developers
MacPaw is building a local version of its AI assistant Eney using Liquid AI's models, according to TechCrunch. The move will offer on-device inference to developers building for MacPaw's app store.
08/05, 19:54
Google Assistant shuts down September 4 as Gemini takes over
Google Assistant is set to shut down on September 4, with Gemini taking over as Google's AI assistant. The deadline, reported by The Tech Buzz, marks a milestone in Google's consolidation of its assistant capabilities under the Gemini brand.
08/05, 19:50
Alibaba Cloud launches One Key MCP service compatible with Qoder, Codex and other agents
Alibaba Cloud has launched One Key MCP, a service compatible with mainstream AI agents such as Qoder and Codex. The offering targets the agent ecosystem with one-click integration, lowering the barrier for developers connecting tools and cloud capabilities.