logo

Not pretty, not Windows-only: npm phishing attack laces popular packages with malware

ID: 1467e5b1-8a91-5fce-9064-0e963feafaf3

STIX ID: report--1467e5b1-8a91-5fce-9064-0e963feafaf3

Feed Name: The Register (Security)

Threat Score
83/100

Date Published: 2025-07-24

Date Updated: 2026-04-26

Author: Tim Anderson

...
...

A supply-chain attack compromised maintainer accounts and published malicious releases of widely used npm packages (notably the "is" package v3.3.1 and several prettier/eslint-related packages). The malware is an obfuscated JavaScript loader that runs on Node.js across macOS, Linux and Windows, captures environment variables and configuration files, exfiltrates data via WebSocket, provides an interactive remote shell, and persists by overwriting index.js; the incident likely originated from phishing using a typosquatted npm clone and affects packages with millions of weekly downloads, posing broad risk to developer machines and downstream applications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.