Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

npm is serving malware to 134,000 developers, and the maintainer can’t stop it

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Kiran Raj
Word Count
2,277
Company Posts That Month
35
Language
English
Hacker News Points
-
Post removed?
No
Summary

The npm accounts for two popular packages, react-native-international-phone-number and react-native-country-select, were hijacked, leading to the release of malicious versions that installed malware. Over three days, the attacker deployed three waves of increasingly stealthy attacks, culminating in a sophisticated use of a dependency chain that obscured the malware's presence. The attacker hijacked the account by changing the email address, locking out the original maintainer and leaving compromised versions active on the npm registry. Detection was challenging due to the removal of obvious signals like preinstall hooks and direct malware files, with the malware instead executing through a chain of dependencies. Endor Labs identified 11 compromised versions using a comprehensive approach that analyzed file hashes, dependency trees, and build-environment fingerprints. The malware utilized the Solana blockchain for communication, making it difficult to block or shut down. This attack exemplifies the evolving nature of supply chain threats and underscores the need for advanced detection methods that go beyond superficial package scanning.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.