<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Hackers Poison 18 Popular NPM Packages with 2.5 Billion Weekly Downloads

Hackers hijack 18 NPM packages using phishing, targeting crypto wallets. NPM swiftly removes threats, minimizing damage.
Content Team

Cybercriminals successfully hijacked 18 widely-used NPM packages after tricking maintainer Josh Junon with a phishing email that appeared to come from NPM support. The fake message directed him to update his two-factor authentication on a lookalike website.

The compromised packages, including popular tools like chalk and debug, collectively see over 2.5 billion weekly downloads. Attackers injected malicious code designed to steal cryptocurrency by intercepting transactions and replacing wallet addresses with their own.

NPM removed the poisoned packages within two hours of the attack being reported. Security firm Wiz estimates the malicious code reached 10% of cloud environments during that brief window, though actual financial damage appears minimal since the attack targeted test addresses rather than real wallets.

Source: Security Week

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo