A sophisticated malware campaign targeting the npm ecosystem has compromised development environments through 60 malicious packages, which are designed to silently collect sensitive network data.
See also: Malicious NPM package uses Unicode steganography

The operation, which began eleven days ago and remains active to this day, highlights the growing threat to supply chains through compromised open source packages.
The malicious packages originate from three npm accounts and have amassed over 3,000 downloads, creating an extensive network of recognition for the attackers. Each package contains identical scripts that are automatically executed after installation via npm, targeting Windows, macOS, and Linux operating systemson developer workstations and continuous integration environments.
Socket.dev researchers detected the campaign through their threat detection systems, revealing that the malware collects hostnames, internal and external IP addresses, DNS server settings , and user paths, before sending this data to a webhook controlled via Discord.
See also: Supply chain attack hits npm package rand-user-agent
The persistence and scale of the operation indicate a well-coordinated mechanism aimed at mapping corporate networks and identifying high-value targets for future attacks.

The attackers published packages through three accounts, with registration emails following the pattern npm9960+[1-3]@gmail.com, and each included exactly twenty malicious packages with legitimate-sounding names, such as “react-xterm2,” “seatable ,” and “garena-admin.” Combined with the rapid publication schedule and identical malicious payloads, this suggests systematic automation in the execution of the campaign.
The extracted data offers attackers extensive network mapping capabilities, connecting private development environments with public infrastructure and revealing organizational relationships that could facilitate targeted breaches.
On continuous integration (CI) servers, malware exposes internal package registry URLs and build paths, information particularly valuable for subsequent attacks in the software supply chain.
See also: Malicious npm package targets Atomic Wallet and Exodus
Based on the above, it is clear that software supply chain attacks are one of the most sophisticated and worrying forms of cyberthreat today. The fact that perpetrators exploit the trust in the open source community – through packages on npm with seemingly legitimate names – makes the attacks particularly insidious and difficult to detect.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
