Home / Companies / Socket / Blog / Post Details
Content Deep Dive

npm ‘is’ Package Hijacked in Expanding Supply Chain Attack -...

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
904
Company Posts That Month
23
Language
English
Hacker News Points
-
Post removed?
No
Summary

An escalating npm phishing campaign has led to the hijacking of the popular 'is' package, embedding cross-platform JavaScript malware in versions 3.3.1 and 5.0.0, which affects developers and CI systems through standard dependency resolution workflows. This sophisticated attack, which began with a typosquatted domain and spoofed emails, compromised several packages by exploiting stolen maintainer credentials to publish rogue versions, notably targeting the 'eslint-config-prettier' and 'eslint-plugin-prettier' packages with malware called Scavenger. This malware includes Windows-specific DLLs with infostealing capabilities, while the 'is' package variant remains in JavaScript, maintaining a live command and control channel and allowing remote shell access. The campaign has forced developers to undertake drastic recovery measures, such as reinstalling operating systems and rotating sensitive credentials, highlighting the serious impact of the attack on the software supply chain.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.