Active Supply Chain Attack: npm Phishing Campaign Leads to P...
Blog post from Socket
Popular npm packages, including eslint-config-prettier and eslint-plugin-prettier, were compromised following a phishing attack that stole a maintainer's token, resulting in the spread of malicious updates. The attack involved a phishing email directing victims to a typosquatted website, npnjs.com, which led to the unauthorized publication of malicious versions of several packages. These compromised releases included potentially harmful code that attempted to execute a DLL on Windows machines, posing a risk of remote code execution. The attack was made more challenging to detect as the malicious versions were published without corresponding commits on GitHub. Maintainers quickly responded by revoking the compromised token, marking the malicious versions as deprecated, and coordinating with npm support to remove them. Developers are advised to check their lockfiles, audit recent installs, enable two-factor authentication, and pin exact versions to protect against similar threats. This incident highlights the vulnerabilities within the software supply chain and the need for vigilant security practices, as phishing attacks on maintainers can quickly escalate into widespread ecosystem threats.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.