HomeSecurityAttack on npm supply chain with minimal profits for hackers

Attack on npm supply chain with minimal profits for hackers

A sophisticated attack on the npm supply chain, which emerged in late August, targeted thousands of downstream projects, injecting malicious payloads into popular JavaScript libraries.

npm supply chain attack

Initial reports pointed to a new variant of the infamous Typosquatting, but further analysis revealed a more sophisticated campaign that exploited compromised administrator credentials to publish backdoored modules under legitimate package names. The attack quickly spread across the ecosystem, affecting applications on enterprise SaaS platforms, development tools, and even educational projects.

Wiz.io researchers observed unusual network activity originating from continuous integration (CI) pipelines shortly after seemingly innocent library updates. While initial telemetry indicated data extraction , closer inspection revealed that the payloads were only executing conditional routines , avoiding direct destructive behavior. The malicious code sampled environment variables, recorded system metadata, and prepared to download secondary payloads from domains controlled by the attackers.

See also: Fake Madgicx Plus and SocialMetrics extensions steal Meta accounts

The attackers minimized detectable anomalies by combining routine package updates and careful versioning strategies to maintain their presence. It is estimated that over 4,500 projects downloaded at least one compromised version before administrators rolled back the affected versions.

npm supply chain attack: Hackers didn't gain much

Despite the broad scope of the attack, analysis of blockchain-based payment channels and cryptocurrency wallets linked to the campaign showed that only a few transactions—totaling less than $200—were completed.

Attack on npm supply chain with minimal profits for hackers

The low economic performance suggests that operators were more interested in reconnaissance and establishing footholds than in immediate profitability, highlighting the evolving motivations behind modern threats to the npm supply chain.

Wiz.io analysts later identified additional indicators of compromise (IoCs) embedded in popular CI logs, including encrypted URLs and base64-encoded data that served as an initial staging point for more complex malware families.

See also: Serious vulnerability in Google Drive Desktop for Windows

Infection Mechanism and Persistence

The malicious packages used a infection mechanism that started with a seemingly innocent postinstall script. Upon installation, the script executes a small loader written in Node.js. This shows how the attacker hid the actual download URL using Base64 encoding to evade simple string matching defenses.

After retrieving the secondary payload, the loader writes a Node.js service file to the user's directory, ensuring automatic execution upon system reboot.

This service introduces a layer of persistence that survives package removal and registry cleanup, essentially giving the attacker long-term access to compromised development environments.

By combining seemingly innocent scripts and encrypted staging, the campaign evaded standard detection mechanisms and highlighted the increasing sophistication of threats in the npm supply chain.

See also: Hacker installed EDR on his system and revealed its activity

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Attack on npm supply chain with minimal profits for hackers

The attack on the npm supply chain reveals once again how vulnerable the open source ecosystem. While the attackers did not make a large financial profit, the campaign showed how easy it is to poison critical dependencies used in thousands of projects. The fact that the malware adopted multi-stage logic and obfuscation techniquesclearly indicates a focus on resilience rather than direct exploitation. This is a serious warning sign: future attacks could be much more destructive if they are activated at scale.

The attackers’ strategy of hiding persistence mechanisms within seemingly harmless scripts highlights the need for more rigorous auditing of open source packages . The community should invest in automated behavior analysis tools, as well as stronger maintainer identification processes. If developers do not adopt zero-trust practices in development, every pipeline risks becoming an Achilles’ heel.

This attack, while limited in financial impact, is a dress rehearsal for more complex campaigns. And that makes security in the software supply chain more critical than ever.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS