HomeSecurityHackers breached npm packages with 2 billion weekly downloads

Hackers breached npm packages with 2 billion weekly downloads

Cybercriminals inserted malware into NPM packages with over 2.6 billion weekly downloadsafter compromising a maintainer's accounts through a phishing attack.

npm packages

Josh Junon, the maintainer whose account was compromised, confirmed the incident, stating that the phishing email came from a domain hosting a website impersonating the legitimate npmjs.com domain.

In the phishing email, the attackers threatened that accounts would be locked on September 10, 2025 (as a scare tactic to get the victim to click on a link that redirected them to a phishing website).

See also: LunaLock ransomware attacks artists

Specifically, the email said:

“As part of our ongoing commitment to account security, we are asking all users to update their two-factor authentication (2FA) credentials. Our records indicate that it has been over 12 months since the last 2FA update… To maintain the security and integrity of your account, we ask that you complete this update as soon as possible. Please note that accounts with outdated 2FA credentials will be temporarily locked starting September 10, 2025, to prevent unauthorized access.”

Several maintainers and developers received the above phishing email.

Since detecting the incident, the NPM team has removed some of the malicious versions published by the attackers, including the one for the debug package, which has 357.6 million downloads per week.

Hackers breached npm packages with 2 billion weekly downloads

According to Aikido Security, which analyzed the supply chain attack, the malicious actors updated the packages after taking control, injecting malicious code that acts as a browser-based interceptor into the index.js files. This can compromise network traffic and application APIs.

The malicious code only affects people who access the compromised applications over the internet, tracking cryptocurrency addresses and transactions that are then redirected to wallet addresses controlled by the attackers.

See also: Hackers abuse Amazon SES for phishing attacks

The malware works by inserting itself into the browser, monitoring wallet addresses Ethereum, Bitcoin, Solana, Tron, Litecoin and Bitcoin Cash In network responses with cryptocurrency transactions, it replaces the destinations with addresses controlled by the attackers and intercepts the transactions before they are signed.

Compromised npm packages

The packages that have been compromised, so far, have a combined total of over 2.6 billion downloads each week.

  • backslash (0.26m downloads per week)
  • chalk-template (3.9m downloads per week)
  • supports-hyperlinks (19.2m downloads per week)
  • has-ansi (12.1m downloads per week)
  • simple-swizzle (26.26m downloads per week)
  • color-string (27.48m downloads per week)
  • error-ex (47.17m downloads per week)
  • color-name (191.71m downloads per week)
  • is-arrayish (73.8m downloads per week)
  • slice-ansi (59.8m downloads per week)
  • color-convert (193.5m downloads per week)
  • wrap-ansi (197.99m downloads per week)
  • ansi-regex (243.64m downloads per week)
  • supports-color (287.1m downloads per week)
  • strip-ansi (261.17m downloads per week)
  • chalk (299.99m downloads per week)
  • debug (357.6m downloads per week)
  • ansi-styles (371.41m downloads per week)

Aikido Security researcher Charlie Eriksensaid the packages were updated to contain a piece of code that would run on a website's client, which silently interferes with crypto and web3 activities in the browser, handles wallet interactions, and rewrites payment destinations so that funds and authorizations are redirected to accounts controlled by the attackers without any visible signs to the user.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

This attack is very dangerous because it works on multiple levels: it alters the content displayed on websites, violates API calls, and manipulates what users' applications believe they are signing.

See also: Over 6,700 private repositories exposed in Nx attack

Hackers breached npm packages with 2 billion weekly downloads

While this is a supply chain, Andrew MacPherson, Principal Security Engineer at Privy, told BleepingComputer that there are specific criteria that must be met for an application to be affected (which significantly reduces the impact):

  • A new installation between ~9 AM and ~11:30 AM ET (when the packages were compromised)
  • Package-lock.json was created during this period
  • Vulnerable packages in direct or transient dependencies

This supply chain attack follows a series of similar attacks targeting developers of various popular JavaScript libraries in recent months. For example, in July, attackers compromised eslint-config-prettier, a package with over 30 million weekly downloads, while in March, ten other widely used npm libraries were compromised and turned into information thieves.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS