Skip to main content
← Back to Demos
Data Loss Prevention beginner · 15 min

Hardcoded API Keys and DB Passwords in Config Files (Keyv npm Worm Pattern)

The Keyv npm worm — first seen in keyv@6.0.0 on August 4, 2026 — spread a credential-stealing preinstall script across hundreds of packages (SafeDep verified 353 poisoned versions across 79 package names; Aikido counts at least 868 packages across 1,381 versions), harvesting repository, registry, cloud and private-key material from developer and CI environments. The same week, 18 malicious npm packages impersonating Alibaba's private @ali-scoped lib-mtop package delivered a cross-platform RAT to developer machines. Both campaigns profit from secrets that sit in plaintext config files: hardcoded API keys, database passwords, registry tokens and .npmrc/.env entries that developers commit to repos and sync across machines. This demo ships a Python config file containing hardcoded API key and database password patterns (synthetic values only, safe to run anywhere). MetaDefender Proactive DLP inspects file content — not just names or metadata — detecting credential patterns such as API key formats, password assignments and token strings, then blocks, quarantines or alerts before secrets spread the way the Keyv worm's payload did.

Attack Technique

Credentials in config files (T1552.001)

MITRE ATT&CK

T1552.001 ↗

Platforms

linux

File Types

.docx

MetaDefender Capabilities

Proactive DLP

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---