HomeSecurityThe NPM package "is" is infected with malware

The NPM package 'is' is infected with malware

The popular NPM package 'is' fell victim to a supply chain attack, in which malware was introduced with a backdoor, giving attackers full access to affected devices.

See also: North Korean hackers distribute 67 malicious npm packages

NPM package is malware

The attack occurred after maintainer accounts were compromised through phishing. This was followed by an unauthorized change of ownership of the package, which went unnoticed for several hours, putting many developers who downloaded the new versions at risk.

The 'is' package is a lightweight JavaScript library that provides a wide variety of functions for type checking and value validation. The software has over 2.8 million weekly downloads from the NPM package index. It is widely used as a low-level dependency in development tools, testing libraries, build systems, as well as backend and command-line (CLI) projects.

On July 19, 2025, the lead maintainer of the NPM 'is' package, John Harband, announced that versions 3.3.1 through 5.0.0 contained malware and were removed about six hours after the attackers submitted them to NPM.

This was a result of the same NPM supply chain attack, in which the fake domain 'npnjs[.]com' to steal maintainer credentials and then publish modified versions of popular packages.

In addition to 'is', the following packages were confirmed to be distributing malware and were compromised as part of the same attack:

  • eslint-config-prettier (versions 8.10.1, 9.1.1, 10.1.6, 10.1.7)
  • eslint-plugin-prettier (versions 4.2.2, 4.2.3)
  • synckit (version 0.11.9)
  • @pkgr/core (version 0.2.8)
  • napi-postinstall (version 0.3.1)
  • got-fetch (versions 5.1.11, 5.1.12)

See also: Hackers target developers with 35 malicious npm packages

According to a report by Socket, the NPM package 'is' contained a cross-platform JavaScript malware loader that opened a WebSocket, allowing remote command execution.

The NPM package 'is' is infected with malware

Researchers also analyzed the malicious payload in the 'eslint' and the remaining affected ones, identifying a Windows infostealer called 'Scavanger', which targets sensitive information stored in browsers.

The malware includes detection evasion, such as indirect syscalls and encrypted communications with the command and control (C2) server, but may trigger security warnings in Chrome due to tampering with security flags.

Based on the attack pattern, it is possible that the attackers have also compromised other credentials and are planning to test more "silent" malicious payloads in new software packages.

To prevent similar attacks, package maintainers are urged to immediately reset passwords and rotate all access tokens. Developers should only use versions that are considered secure, i.e. those released before July 18, 2025.

See also: 60 malicious npm packages collect sensitive network data

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Additionally, automatic package updates should be disabled , while the use of lockfiles is recommended for “freezing” dependencies at specific, tested versions.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS