logo

More packages poisoned in npm attack, but would-be crypto thieves left pocket change

ID: 9396c2e9-d264-5b3d-8a39-6f2893e367a4

STIX ID: report--9396c2e9-d264-5b3d-8a39-6f2893e367a4

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2025-09-09

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

A phishing-driven supply-chain attack compromised an npm maintainer’s account, allowing attackers to publish malware-laced versions of widely used packages (initially 18 Qix packages, later additional DuckDB and coveops/abi packages). The malicious releases were found in about 10% of cloud environments and could still be available for download; despite large scale potential, on-chain analysis shows only around $925 stolen, and researchers warn organizations to assume malicious package versions may persist and to harden supply-chain and credential defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.