DuckDB npm Account Compromised in Continuing Supply Chain At...
Blog post from Socket
A recent npm supply chain attack, which previously targeted the prolific author Qix, has expanded to compromise the DuckDB npm account, affecting several DuckDB-related packages. The account breach led to the publication of malicious versions of packages, including [email protected], @duckdb/[email protected], @duckdb/[email protected], and @duckdb/[email protected], which have significant weekly downloads. These compromised versions contain the same wallet-drainer malware used in the Qix incident, designed to detect connected crypto wallets and alter transaction data by replacing legitimate cryptocurrency addresses with those controlled by the attacker. Despite some malicious releases being deprecated and removed from npm, they remained live for several hours, reflecting a continuing threat to the software supply chain.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.