Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

npm Account Takeovers are a Growing Malware Trend

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Jenn Gile
Word Count
2,311
Company Posts That Month
10
Language
English
Hacker News Points
-
Post removed?
No
Summary

In 2025, the npm ecosystem faced a significant increase in security threats, particularly Account Takeovers (ATOs), where attackers gain access to legitimate open-source projects to distribute malware. ATOs are attractive to threat actors because they exploit trusted projects and evade conventional security measures, leading to a 15.3x rise in malicious npm packages compared to 2024. Five major ATO campaigns in 2025 highlighted vulnerabilities in the npm ecosystem, including phishing attacks on maintainers and exploiting GitHub vulnerabilities. These campaigns affected key JavaScript packages like eslint-config-prettier, is, and chalk, leading to the compromise of developer machines and CI/CD pipelines through tactics such as Remote Code Execution and JavaScript malware loaders. Despite improvements by GitHub, such as Trusted Publishing and session-based authorization, challenges remain, particularly for maintainers using unsupported CI/CD platforms. The attacks underscore the ongoing need for enhanced security measures and awareness in the open-source community.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 8 1,162 174 80 -4%
Real-time 2 4,546 943 215 -38%
AI Guardrails 1 273 91 47 -29%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.