Home / Companies / JFrog / Blog / Post Details
Content Deep Dive

New compromised packages identified in largest npm attack in history

Blog post from JFrog

Post Details
Company
Date Published
Author
Andrey Polkovnichenko, JFrog Security Researcher
Word Count
514
Company Posts That Month
17
Language
English
Hacker News Points
-
Post removed?
No
Summary

A recent phishing campaign compromised the npm registry by publishing trojanized versions of 18 popular packages, including "debug," "chalk," and "ansi-styles," after obtaining developers’ tokens. The malicious code, obfuscated with the "javascript-obfuscator" library, contained a cryptocurrency stealer that intercepted web3 transactions, redirecting funds to the attacker's wallet. Despite its widespread reach, affecting packages with over two billion total downloads, the attack caused minimal practical damage, with only about $500 in cryptocurrency stolen due to the quick detection of the poorly obfuscated malware. This incident, the largest supply chain attack in npm’s history, underscores the fragility of the JavaScript ecosystem, where many utilities depend on single developers. Further compromised accounts, such as "duckdb," suggest the campaign is ongoing, and continuous monitoring is underway to update any new developments.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.