npm Account Takeovers are a Growing Malware Trend
Blog post from Endor Labs
In 2025, the npm ecosystem faced a significant increase in security threats, particularly Account Takeovers (ATOs), where attackers gain access to legitimate open-source projects to distribute malware. ATOs are attractive to threat actors because they exploit trusted projects and evade conventional security measures, leading to a 15.3x rise in malicious npm packages compared to 2024. Five major ATO campaigns in 2025 highlighted vulnerabilities in the npm ecosystem, including phishing attacks on maintainers and exploiting GitHub vulnerabilities. These campaigns affected key JavaScript packages like eslint-config-prettier, is, and chalk, leading to the compromise of developer machines and CI/CD pipelines through tactics such as Remote Code Execution and JavaScript malware loaders. Despite improvements by GitHub, such as Trusted Publishing and session-based authorization, challenges remain, particularly for maintainers using unsupported CI/CD platforms. The attacks underscore the ongoing need for enhanced security measures and awareness in the open-source community.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 8 | 1,162 | 174 | 80 | -4% |
| Real-time | 2 | 4,546 | 943 | 215 | -38% |
| AI Guardrails | 1 | 273 | 91 | 47 | -29% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.