What’s in your npm stat counter? A love doll store—we hope n...
Blog post from Socket
The npm package "state-counter" was identified as a deceptive component masquerading as a legitimate statistical tool, but instead contained obfuscated code leading to an NSFW website, thereby raising significant security concerns. This package, which had nearly 1000 downloads, utilized brandjacking and typosquatting techniques to mislead users into believing it was affiliated with the legitimate StatCounter service. Despite containing complex obfuscation and misleading attributions to Twitter, it ultimately redirected users to an adult store, specifically targeting China-based developers and users. Although not as malicious as other npm packages that have launched cryptominers or ransomware, "state-counter" still posed a risk to the open source ecosystem's security and integrity. The package was promptly reported to npm and removed by GitHub's security team following its discovery by Socket, which continues to monitor and identify similar unwanted components threatening the software supply chain.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.