Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Active Supply Chain Attack: npm Phishing Campaign Leads to P...

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
566
Company Posts That Month
23
Language
English
Hacker News Points
-
Post removed?
No
Summary

Popular npm packages, including eslint-config-prettier and eslint-plugin-prettier, were compromised following a phishing attack that stole a maintainer's token, resulting in the spread of malicious updates. The attack involved a phishing email directing victims to a typosquatted website, npnjs.com, which led to the unauthorized publication of malicious versions of several packages. These compromised releases included potentially harmful code that attempted to execute a DLL on Windows machines, posing a risk of remote code execution. The attack was made more challenging to detect as the malicious versions were published without corresponding commits on GitHub. Maintainers quickly responded by revoking the compromised token, marking the malicious versions as deprecated, and coordinating with npm support to remove them. Developers are advised to check their lockfiles, audit recent installs, enable two-factor authentication, and pin exact versions to protect against similar threats. This incident highlights the vulnerabilities within the software supply chain and the need for vigilant security practices, as phishing attacks on maintainers can quickly escalate into widespread ecosystem threats.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.